CVE-2026-20349: Actively Exploited Cisco ASA and FTD Flaw Enables Remote DoS
ID: 1fb240c9-a76e-5ed8-9b98-05137a8e1683
STIX ID: report--1fb240c9-a76e-5ed8-9b98-05137a8e1683
Feed Name: SOC Prime Blog
Threat Score
Cisco disclosed CVE-2026-20349, a high-severity (CVSS 8.6) vulnerability in ASA and Secure FTD Remote Access SSL VPN that allows unauthenticated remote attackers to send crafted HTTP requests to force affected appliances to reload, producing a denial-of-service; active exploitation was observed in August 2026, CISA added it to its KEV catalog, and Cisco published hotfixes and detection guidance with no complete workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
