CyberNews
← Back to dashboard
NEWS BleepingComputer

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Aug 11, 2026, 07:45 PM · by BleepingComputer

Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices.

The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled.

In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco explains in the advisory.

"A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."

Source: BleepingComputer