Threat Bulletin

Cisco ASA and FTD Remote Access VPN Flaw Actively Exploited to Crash Devices

Alert essentials:
Cisco disclosed CVE-2026-20349, a high-severity (CVSS 8.6) denial-of-service flaw in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software, and confirmed active exploitation in the wild as of August 2026. An unauthenticated attacker can send a single crafted HTTP request to force an affected device to reload. Cisco has released hot fixes for all affected ASA and FTD trains; there are no workarounds. This CVE is not yet listed in the CISA KEV catalog, but organizations running Remote Access VPN, SSL VPN, or Zero Trust Network Access on ASA/FTD should patch immediately.

Email Team


Detailed threat description:
The vulnerability stems from insufficient error checking as Cisco Secure Firewall ASA and FTD software parses HTTP requests sent to the Remote Access SSL VPN service. Devices become exposed whenever an SSL listen socket is active — which occurs when IKEv2 Remote Access VPN with client services, SSL VPN, or (on FTD) Zero Trust Network Access is configured. An attacker needs no credentials and no user interaction: a single malformed HTTP request to the VPN-facing interface is enough to crash the device and force a reload, interrupting all VPN and traffic-inspection services running on it. Cisco’s Firewall Management Center (FMC) software is confirmed not affected, since it does not terminate VPN sessions itself.

Cisco’s Product Security Incident Response Team (PSIRT) became aware of active exploitation in August 2026 but has not disclosed the threat actor, targeting pattern, or any indicators of compromise, and the advisory does not describe symptoms beyond unexpected device reloads. The flaw was found both during Cisco’s internal testing and independently reported by researcher Valerio Brussani. Because ASA and FTD appliances are frequently deployed as perimeter VPN gateways — and Cisco firewalls have been a recurring target of sophisticated, persistent campaigns such as ArcaneDoor over the past two years — any exposed, unpatched device should be treated as a priority remediation target even though this particular flaw causes disruption rather than code execution.

Impacts on healthcare organizations:
Healthcare organizations rely heavily on ASA and FTD appliances to provide secure remote access for clinicians, remote staff, and third-party vendors connecting to EHR systems and clinical networks. A successful DoS attack can force repeated device reloads, cutting off remote clinical access and interrupting site-to-site connectivity between facilities during patient care hours. Repeated or sustained exploitation could be used to mask a separate intrusion attempt or to pressure a target during a ransomware negotiation, and any unplanned outage of a HIPAA-regulated network perimeter device warrants review under an organization’s incident response and business-continuity procedures.

Affected Products

CVE Impacted Versions Fix CVSS CWE CISA KEV Tenable Plugin EOL/EOS
CVE-2026-20349 ASA 9.16, 9.18, 9.20, 9.22, 9.23, 9.24;
FTD 7.0, 7.2, 7.4, 7.6, 7.7, 10.0
(with SSL listen enabled)
Hot fixes per train
(see Recommendations)
8.6 (Vendor) CWE-244 No
(as of Aug 11, 2026)
Pending
not yet published
Supported

Vulnerable only if IKEv2 Remote Access VPN with client services, SSL VPN, or (FTD only) Zero Trust Network Access is enabled. Verify with: show asp table socket | include SSL — presence of an SSL LISTEN socket indicates exposure

Recommendations

  • Patch immediately — no workaround exists. Install the Cisco-provided hot fix matching your running release via the Cisco Software Center (software.cisco.com/download/home):
    • ASA 9.16 → hot fix 89.16.4.50 | ASA 9.18 → 89.18.4.50 | ASA 9.20 → 9.20.4.235
    • ASA 9.22 → 9.22.3.191 | ASA 9.23 → 9.23.1.211 | ASA 9.24 → 9.24.1.221
    • If applying an ASA hot fix beginning with “89,” also upgrade ASDM to 7.24.1.374 — earlier ASDM releases do not recognize this numbering format
    • FTD 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 → apply the corresponding Cisco_FTD_Hotfix package listed in advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF via Cisco Secure FMC
  • Confirm exposure before and after patching:
    • Run show asp table socket | include SSL on each ASA/FTD device to identify active SSL listen sockets
    • Review Devices > VPN > Remote Access in FMC (or Remote Access VPN in FDM) to confirm which devices have RA VPN, SSL VPN, or ZTNA enabled
  • Use the Cisco Software Checker (sec.cloudapps.cisco.com/security/center/softwarechecker.x) to validate your exact running version against this advisory before and after remediation.
  • Monitor for unplanned reloads: correlate unexpected ASA/FTD reload events in syslog/SNMP with VPN-facing interfaces during the remediation window, since Cisco has not published IOCs for this campaign.
  • Track CISA KEV and Tenable coverage: this CVE was not yet in the CISA KEV catalog and had no published Tenable plugin ID as of this bulletin — re-check both before closing out remediation tracking.

References


A Message for Fortified
Fortified Health Security is committed to maturing the cybersecurity posture of your healthcare organization. We will monitor and update this bulletin as the situation progresses.

Should you have any questions about this threat, or any other issue you are facing, please reach out to us. We’re here to help you on your cybersecurity journey.

Email: connect@fortifiedhealthsecurity.com Phone: 615-600-4002 Web: www.fortifiedhealthsecurity.com

Share