A critical vulnerability in Cisco's Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) has been identified, tracked as CVE-2026-20349. This flaw allows unauthenticated attackers to remotely crash the firewall, designated with a CVSS score of 8.6 (High). The vulnerability affects multiple versions of the ASA and FTD software and is already being actively exploited. Cisco recommends urgent upgrading to fixed releases, as no workarounds are available. The flaw arises from weak input validation in the Remote Access SSL VPN service, enabling denial of service conditions.
Cisco ASA/FTD flaw lets attackers crash firewalls, CVE-2026-20349
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Cisco ASA/FTD flaw lets attackers crash firewalls, CVE-2026-20349
securityonline.info
-
CISA Logs CVE-2026-72898 Metabase Flaw in KEV Catalog
cybersixt.com
-
CISA adds Cisco firewall heap flaw CVE-2026-20349 to KEV catalog
cybersixt.com
-
CISA adds critical Metabase SQLi flaw to KEV, urges patch
cybersixt.com
-
Cisco ASA/FTD heap bug lets remote attackers crash firewalls
cybersixt.com