Ethical Hacking News
A high-severity vulnerability in Cisco ASA and FTD Software has been exploited in the wild, allowing an unauthenticated remote attacker to trigger a denial-of-service (DoS) condition. Organizations must apply the latest patches immediately and maintain proactive measures to prevent unauthorized access.
Cisco has issued a high-severity vulnerability alert for its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The vulnerability, CVE-2026-20349, is rated at 8.6 on the Common Vulnerability Scoring System (CVSS), indicating a significant risk to network security. The vulnerability is related to insufficient error checking when processing HTTP requests, which could allow an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition. Fixed versions are available for ASA and FTD Software, with specific versions listed in the context. Cisco has confirmed there are currently no workarounds to address the vulnerability, recommending immediate patch application. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by August 14, 2026.
Cisco has issued a high-severity vulnerability alert for its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software, which has been exploited in the wild. The vulnerability, tracked as CVE-2026-20349, is rated at 8.6 on the Common Vulnerability Scoring System (CVSS), indicating a significant risk to network security.
The vulnerability is related to insufficient error checking when processing HTTP requests, which could allow an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition. This means that if an attacker sends a crafted HTTP request to the Remote Access SSL VPN service on an affected device, they can cause the device to reload, resulting in a DoS condition.
The security defect impacts devices running vulnerable versions of ASA and FTD Software, which are listed below:
ASA 9.161 - Fixed in 89.16.4.50
ASA 9.181 - Fixed in 89.18.4.50
ASA 9.20 - Fixed in 9.20.4.235
ASA 9.22 - Fixed in 9.22.3.191
ASA 9.23 - Fixed in 9.23.1.211
ASA 9.24 - Fixed in 9.24.1.221
FTD 7.0 - Fixed in Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar
FTD 7.2 - Fixed in Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar
FTD 7.4 - Fixed in Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar
FTD 7.6 - Fixed in Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar
FTD 7.7 - Fixed in Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar
FTD 10.0 - Fixed in Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar
Cisco has confirmed that there are currently no workarounds to address the vulnerability, and it is recommended that users apply the latest patches as soon as possible.
The development of this vulnerability has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by August 14, 2026.
It is worth noting that Cisco has credited Valerio Brussani for separately discovering and reporting the vulnerability. However, there are currently no details available about the nature of the attacks, the identity and origins of the threat actor exploiting the vulnerability, what organizations have been targeted, and if any of those efforts were successful.
The exploitation of this vulnerability highlights the importance of keeping software up-to-date and applying patches as soon as possible to prevent unauthorized access and maintain network security. It is essential for organizations to stay vigilant and take proactive measures to protect their networks from such threats.
Furthermore, the fact that there are currently no workarounds available underlines the need for continuous monitoring and patch management practices. Organizations must ensure that they have robust systems in place to detect and respond to vulnerabilities promptly to prevent exploitation.
In conclusion, the Cisco ASA and FTD vulnerability is a significant threat to network security, and organizations must take immediate action to address this issue. By applying the latest patches and maintaining a proactive approach to patch management, organizations can mitigate the risk of unauthorized access and ensure their networks remain secure.
Related Information:
https://www.ethicalhackingnews.com/articles/Cisco-ASA-and-FTD-Vulnerability-Exploitation-A-Growing-Threat-to-Network-Security-ehn.shtml
https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
https://nvd.nist.gov/vuln/detail/CVE-2026-20349
https://www.cvedetails.com/cve/CVE-2026-20349/
Published: Wed Aug 12 03:37:16 2026 by llama3.2 3B Q4_K_M