← Vulnerability feed

Vulnerability record · CVE-2026-20349 · published 11 August 2026

CVE-2026-20349: Cisco ASA and FTD SSL VPN HTTP request handling denial of service

Cisco · Adaptive Security Appliance Software

Cisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unauthenticated remote attacker can send a crafted HTTP request that causes the device to reload, producing a denial of service. Because the affected devices are internet-facing VPN gateways, a successful hit can take remote-access connectivity offline for all users of that appliance.

8.6 CVSS 3.1 High CISA KEV since 11 Aug 2026 EPSS 1.0% · top 38.3% CWE-244 · CWE-244
8.6CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
16 Sep 2026Last modified by NVD

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service against internet-facing VPN gateways that is listed in CISA KEV with a short remediation deadline, though it causes availability loss rather than code execution or data compromise.

What it is

Cisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unauthenticated remote attacker can send a crafted HTTP request that causes the device to reload, producing a denial of service. Because the affected devices are internet-facing VPN gateways, a successful hit can take remote-access connectivity offline for all users of that appliance.

Impact

The attacker gains no code execution or data access; the effect is a forced device reload and loss of availability for the SSL VPN service and any traffic handled by the appliance. Repeated exploitation can keep the firewall offline, disrupting remote access and network perimeter enforcement.

Attack surface

Reachable over the network through the Remote Access SSL VPN service, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required; the attacker only needs network access to the exposed SSL VPN endpoint.

Exploitation

CVE-2026-20349 is listed in CISA's Known Exploited Vulnerabilities catalog with a due date of 2026-08-14, indicating active exploitation. EPSS is 0.02213 (81.7th percentile), so the statistical model rates near-term exploitation probability as modest despite the KEV listing.

What to do

  • Apply the Cisco vendor advisory fix for ASA and FTD SSL VPN software as the first action; follow CISA BOD 26-04 patching guidance.
  • If patching cannot be completed immediately, restrict or disable internet-facing Remote Access SSL VPN access and apply the mitigations in the Cisco advisory.
  • Limit exposure of SSL VPN interfaces to trusted sources where operationally feasible, and monitor for unexpected device reloads.
  • Track remediation against the CISA KEV due date of 2026-08-14 and escalate any unpatched internet-exposed appliances.
  • Review device reload and crash logs after patching to confirm no further unexpected restarts occur.

Detection

  • Monitor ASA/FTD logs for unexpected reloads, crash dumps or restart events correlated with inbound SSL VPN HTTP traffic.
  • Alert on anomalous or malformed HTTP requests to the SSL VPN service, especially from untrusted sources.
  • Track availability of SSL VPN endpoints and alert on sudden loss of service or session drops consistent with a device reload.
  • Correlate repeated reload events across the same appliance to distinguish exploitation attempts from unrelated hardware or power faults.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalog on 11 August 2026 as "Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 14 August 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20349 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-20349), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.