Cyber Security News

Cisco Firewall 0-Day Vulnerability Exploited in the Wild to Trigger DoS Condition

Security teams managing Cisco edge infrastructure face a high-priority patching deadline after Cisco confirmed active exploitation of a newly disclosed zero-day in its firewall VPN stack.

Tracked as CVE-2026-20349, the flaw affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software and can force an unexpected device reload, creating a denial-of-service condition for remote access and related network paths.

According to Cisco’s security advisory, the vulnerability stems from insufficient error checking when the SSL VPN service processes HTTP requests. An unauthenticated remote attacker can exploit the issue by sending a crafted HTTP request to the Remote Access SSL VPN service on an exposed device. No valid credentials are required.

A successful attack causes the appliance to reload, interrupting VPN sessions and any traffic that depends on the firewall remaining online. Because many organizations place ASA and FTD devices at the network perimeter, even a short reload window can disrupt remote workers, site-to-site connectivity, and business-critical applications.

Cisco Firewall 0-Day Vulnerability

Cisco’s Product Security Incident Response Team (PSIRT) stated that it became aware of in-the-wild exploitation in August 2026. The company strongly urges customers to move to fixed software rather than rely on temporary controls.

There are no workarounds that fully address the vulnerability. The issue was discovered during internal security testing and was also reported to Cisco by researcher Valerio Brussani (@val_brux of harmonyguard.cloud).

Not every Cisco firewall deployment is automatically at risk. Devices are vulnerable only when they run an affected ASA or FTD release and have certain features enabled that open SSL listen sockets.

Those configurations include SSL VPN with WebVPN enabled on an interface, IKEv2 Remote Access VPN with client services, and, on FTD only, Zero Trust Network Access when that feature is turned on.

Cisco has confirmed that Cisco Secure Firewall Management Center (FMC) Software is not affected. Administrators can verify exposure by reviewing the running configuration for WebVPN, IKEv2 client-services, or zero-trust enablement, and by checking software versions against Cisco’s Fixed Software guidance.

Cisco has published hot fixes for multiple ASA trains, including releases in the 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 branches, as well as corresponding FTD hot fixes for 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 lines across supported platforms. Hot fixes are available from the Cisco Software Center.

For ASA hot fixes whose names begin with “89,” Cisco notes that ASDM Release 7.24.1.374 or later is required so the management interface correctly recognizes the new numbering format. Customers who prefer a full release upgrade can use the Cisco Software Checker to identify the earliest fixed release for their platform and build.

From an operational standpoint, defenders should treat internet-facing SSL VPN listeners as the primary attack surface. Priority should go to appliances with remote access VPN or zero-trust features enabled, especially those reachable from untrusted networks.

After patching, teams should validate VPN availability, review device reload history, and monitor for anomalous HTTP traffic aimed at VPN portals. Cisco’s full advisory, including fixed software tables and configuration checks, is published at the Cisco Security Center.

For organizations that depend on Cisco ASA or FTD for secure remote access, CVE-2026-20349 is a clear reminder that perimeter VPN services remain a favored target when unauthenticated DoS bugs surface.

Applying vendor hot fixes or upgraded releases promptly is the only reliable path to closing the exposure while exploitation is already underway.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago