
CISA has added CVE‑2026‑20349 to its Known Exploited Vulnerabilities catalogue after confirming that the flaw in Cisco Secure Firewall ASA and FTD products is being actively exploited in the wild according to the latest KEV entry. The vulnerability allows an unauthenticated attacker to trigger a denial of service by sending specially crafted packets to the Remote Access SSL VPN service.
Tracked as a heap inspection issue, CVE‑2026-20349 carries a CVSS v3.1 score of 8.6, rated HIGH as detailed in Cisco’s advisory. The flaw stems from insufficient validation of user‑supplied data within the VPN daemon, which can lead to memory corruption and a crash of the firewall process. Multiple versions of ASA and FTD software are affected, and Cisco has stated that no workaround is available.
Evidence of active exploitation has been observed since early August 2026, with security researchers noting attempts to overwhelm VPN endpoints as reported by securityonline.info. Threat actor profiling links the activity to groups such as Lazarus Group (G0032) KP, which have previously targeted network edge devices for disruption. The addition to the KEV catalogue underscores that the vulnerability is not theoretical but poses an immediate risk.
The KEV catalogue, maintained by CISA, serves as a prioritisation guide for federal agencies and private organisations seeking to focus patching efforts on vulnerabilities known to be exploited according to CISA’s own description. By logging CVE‑2026-20349, the agency highlights the need for timely mitigation alongside other recent entries such as the Metabase SQL injection and Windows WinSock use‑after‑free flaws. This helps defenders allocate resources where they are most needed.
Network administrators should immediately consult Cisco’s security advisory to identify the affected software versions and apply the recommended upgrades as specified in the vendor’s fix. Where immediate patching is not feasible, organisations should consider restricting VPN access to trusted networks, enabling strict access control lists, and monitoring for abnormal resource consumption or sudden restarts on ASA/FTD devices.
Finally, defenders are encouraged to review their asset inventories for any exposed SSL VPN interfaces, verify that logging is enabled for VPN daemon events, and subscribe to CISA alerts for future KEV updates via the KEV catalogue. Prioritising these steps will reduce the likelihood of a successful denial of service attack against critical perimeter defences.