---
title: "Cisco Secure Firewall ASA/FTD Remote Access SSL VPN Denial of Service Vulnerability (Actively Exploited)"
summary: "Unauthenticated denial-of-service vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD software. A remote attacker can send a single crafted HTTP request to the RA VPN endpoint and force the appliance to reload, dropping every active VPN session and briefly taking the perimeter offline. Cisco PSIRT confirmed in-the-wild exploitation in August 2026 and CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalog on 11 August 2026. There is no workaround."
severity: high
status: active
advisoryId: "GARNET-CSIRT-2026-004"
published: 2026-08-18
affected:
  - "Cisco Secure Firewall ASA Software"
  - "Cisco Secure Firewall Threat Defense (FTD) Software"
cves:
  - "CVE-2026-20349"
tags:
  - "cisco"
  - "kev"
  - "ssl-vpn"
  - "active-exploitation"
tlp: CLEAR
references:
  - title: "Cisco · cisco-sa-asaftd-vpn-dos-dzv4mQFF"
    url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF"
  - title: "CISA · Known Exploited Vulnerabilities Catalog"
    url: "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20349"
  - title: "Cisco Software Checker"
    url: "https://sec.cloudapps.cisco.com/security/center/softwarechecker.x"
draft: false
---

## Summary

Unauthenticated denial-of-service vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD software. A remote attacker can send a single crafted HTTP request to the RA VPN endpoint and force the appliance to reload, dropping every active VPN session and briefly taking the perimeter offline. Cisco PSIRT confirmed in-the-wild exploitation in August 2026 and CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalog on 11 August 2026. There is no workaround.


## Impact

Exploitability signals: **CVSS 8.6** · **active exploitation** confirmed by Cisco PSIRT · **CISA KEV listed** 11 August 2026 (US federal remediation deadline of 14 August 2026 has passed) · unauthenticated, remote, no user interaction.

Impact is availability only : no code execution, no data exposure. But the affected device is typically the institution's remote-access gateway and edge firewall. A successful attack forces the appliance to reload, cutting off VPN access and interrupting traffic in flight; repeated exploitation keeps the service down for as long as the attacker sustains it.


## Affected systems

Cisco Secure Firewall ASA or FTD software running an unpatched release **and** with at least one of the following features configured (these enable the SSL listen socket that hosts the vulnerable service):

- **SSL VPN** — `webvpn enable <interface>`
- **IKEv2 Remote Access VPN with client services** — `crypto ikev2 enable <interface> client-services port <n>`
- **Zero Trust Network Access** (FTD only) — `zero-trust enable`

Cisco has confirmed that **Cisco Secure Firewall Management Center (FMC) is not affected**.

## Action

1. **Determine whether you are exposed.** On the ASA/FTD CLI, check whether any of the three feature blocks above are configured on an interface. If none are enabled, the device is not exposed via this path. If any are, treat as vulnerable pending patch verification.
2. **Identify your exact software release** and use the [Cisco Software Checker](https://sec.cloudapps.cisco.com/security/center/softwarechecker.x) to look up the fixed build for your train. Cisco has published hot fixes for ASA 9.16 through 9.24 and FTD 7.0 through 10.0 — see the advisory's Fixed Software table for the exact hot fix filename per release.
3. **Patch on an emergency schedule.** No workaround exists. CISA's federal remediation deadline of 14 August has already passed; if you have not patched, treat this as a week-of change rather than a cycle-of change.
4. **Enable detection at the perimeter.** Cisco has published Snort rules **SID 46897** and **SID 59654** for this vulnerability. Institutions running Firepower/Snort-based inspection should confirm both are enabled and alerting.
5. **Reduce management-plane exposure.** The RA VPN listener has to be internet-reachable to serve remote users, but the ASA/FTD management interface (HTTPS admin, SSH) should not be. Confirm access-control lists restrict management access to trusted networks.
6. **Report unexplained reloads.** Cisco has not released indicators of compromise. Any member institution observing unexpected ASA/FTD reloads from August 2026 onward should [report the incident](https://csirt.garnet.edu.gh/report/) so we can correlate across the constituency.
