Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed zero-day in its firewall VPN stack.

Tracked as CVE-2026-20349, the flaw affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software and can force an unexpected device reload, creating a denial-of-service condition for remote access and related network paths.

According to Cisco’s security advisory, the vulnerability stems from insufficient error checking when the SSL VPN service processes HTTP requests. An unauthenticated remote attacker can exploit the issue by sending a crafted HTTP request to the Remote Access SSL VPN service on an exposed device. No valid credentials are required.

A successful attack causes the appliance to reload, interrupting VPN sessions and any traffic that depends on the firewall remaining online. Because many organizations place ASA and FTD devices at the network perimeter, even a short reload window can disrupt remote workers, site-to-site connectivity, and business-critical applications.

Cisco Firewall 0-Day Vulnerability

Cisco’s Product Security Incident Response Team (PSIRT) stated that it became aware of in-the-wild exploitation in August 2026. The company strongly urges customers to move to fixed software rather than rely on temporary controls.

There are no workarounds that fully address the vulnerability. The issue was discovered during internal security testing and was also reported to Cisco by researcher Valerio Brussani (@val_brux of harmonyguard.cloud).

Not every Cisco firewall deployment is automatically at risk. Devices are vulnerable only when they run an affected ASA or FTD release and have certain features enabled that open SSL listen sockets.

Those configurations include SSL VPN with WebVPN enabled on an interface, IKEv2 Remote Access VPN with client services, and, on FTD only, Zero Trust Network Access when that feature is turned on.

Cisco has confirmed that Cisco Secure Firewall Management Center (FMC) Software is not affected. Administrators can verify exposure by reviewing the running configuration for WebVPN, IKEv2 client-services, or zero-trust enablement, and by checking software versions against Cisco’s Fixed Software guidance.

Cisco has published hot fixes for multiple ASA trains, including releases in the 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 branches, as well as corresponding FTD hot fixes for 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 lines across supported platforms. Hot fixes are available from the Cisco Software Center.

For ASA hot fixes whose names begin with “89,” Cisco notes that ASDM Release 7.24.1.374 or later is required so the management interface correctly recognizes the new numbering format. Customers who prefer a full release upgrade can use the Cisco Software Checker to identify the earliest fixed release for their platform and build.

From an operational standpoint, defenders should treat internet-facing SSL VPN listeners as the primary attack surface. Priority should go to appliances with remote access VPN or zero-trust features enabled, especially those reachable from untrusted networks.

After patching, teams should validate VPN availability, review device reload history, and monitor for anomalous HTTP traffic aimed at VPN portals. Cisco’s full advisory, including fixed software tables and configuration checks, is published at the Cisco Security Center.

For organizations that depend on Cisco ASA or FTD for secure remote access, CVE-2026-20349 is a clear reminder that perimeter VPN services remain a favored target when unauthenticated DoS bugs surface.

Applying vendor hot fixes or upgraded releases promptly is the only reliable path to closing the exposure while exploitation is already underway.