Cisco Barcelona
– Giacomo Lee/SDxCentral

Cisco flagged a major flaw in its firewall provision that rendered software susceptible to a denial-of-service (DoS) condition.

Tracked as CVE-2026-20349, the flaw affects two services in Cisco's Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD). Fallible to insufficient error checking when processing HTTP requests, the vulnerability can be exploited with the deployment of a crafted HTTP request to the Remote Access SSL VPN service on an affected device.

The flaw in question affect three elements across both suites: IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access. According to Cisco, a successful exploit could allow the actor to cause the affected device to reload, resulting in a DoS condition.

Cisco issued hot fixes for ASA covering releases 9.16.1, 9.18.1, 9.20, 9.22, 9.23 and 9.24. FTD hot fixes are available across releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.

The firm confirmed the vulnerability is being actively exploited, marking the issue with its maximum severity rating.