CISA has added CVE‑2026‑20349 to its Known Exploited Vulnerabilities (KEV) catalogue. The entry concerns Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) products and is titled “Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability”.
The flaw allows an unauthenticated, remote attacker to trigger a heap inspection error that causes the device to reload unexpectedly, resulting in a denial‑of‑service condition.
The vulnerability is a heap‑based memory inspection issue that can be exploited over the network without authentication. Successful exploitation leads to an unplanned reload of the ASA or FTD appliance, disrupting traffic and producing a DoS effect. CISA lists the CVSS v3.1 score as 8.6, rating the severity as HIGH. At the time of the KEV addition, no patch had been released and the patch status is marked as unknown.
Active exploitation has been observed, which is why the CVE appears in the KEV catalogue. No ransomware campaign has been publicly linked to this vulnerability. CISA has set a remediation deadline of 14 August 2026 for federal agencies to address the issue.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Stakeholders must evaluate each asset’s internet exposure and follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
While the directive binds Federal Civilian Executive Branch (FCEB) agencies, all organisations should review their exposure to ASA and FTD devices and apply any available mitigations promptly.
For full technical details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-20349 and the CISA KEV catalogue.