Cisco reports that a vulnerability capable of crashing its Secure Firewall ASA and FTD appliances is already being exploited in live attacks. A single crafted HTTP request is enough for an unauthenticated, remote attacker to force a device reload and take the firewall offline.
The flaw, CVE-2026-20349 (CVSS 8.6), stems from insufficient error checking while the software processes HTTP requests. The trigger is a crafted request sent to the Remote Access SSL VPN service on an affected device.
Exposure depends on configuration as much as version. Devices running a vulnerable ASA or FTD release become reachable when they enable IKEv2 Remote Access VPN with client services, the SSL VPN webvpn service, or Zero Trust Network Access.
Fixed ASA versions include 9.16.4.50, 9.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, and 9.24.1.221. Cisco’s advisory lists matching fixed releases for Secure Firewall Threat Defense, and admins should check the entry for their exact version.
A firewall reload interrupts VPN tunnels, policy enforcement, and traffic inspection for every user behind the box. Teams running exposed configurations should treat this as a priority patch and watch for probes aimed at the DoS trigger.
