Cisco warns of firewall flaw being actively exploited to crash devices

Cisco has disclosed a high-severity denial-of-service vulnerability in its Secure Firewall ASA and Threat Defense software that is being actively exploited in attacks, the company said in a security advisory published today. The flaw, tracked as CVE-2026-20349 with a severity score of 8.6, can be triggered remotely without authentication by sending a crafted HTTP request to affected devices with remote access services enabled, causing them to reload and go offline.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco said. A successful attack "could allow the attacker to cause the affected device to reload, resulting in a DoS condition." Vulnerable configurations include IKEv2 Remote Access VPN, SSL VPN and Zero Trust Network Access on FTD devices. Cisco has released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0, and said there are no workarounds. The company became aware of active exploitation in August 2026 but has not disclosed who is behind the attacks or which organizations are targeted, Reuters is reporting, Lawrence Abrams reports for BleepingComputer.