Vulnerability Notification – Cisco ASA and FTD Remote Access VPN DoS Actively Exploited
Created: Thursday, August 13, 2026 - 16:35
Categories:
(TLP:CLEAR) ACTION MAY BE REQUIRED for utilities using Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) Software with Remote Access SSL VPN, IKEv2 Remote Access VPN (with client services), or Zero Trust Network Access (ZTNA) enabled. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
A high-severity denial-of-service (DOS) vulnerability affecting Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) Software is being actively exploited in the wild. Tracked as CVE-2026-20349 (CVSS 8.6), the vulnerability stems from insufficient error checking when the Remote Access SSL VPN service processes HTTP requests. Successful exploitation could allow an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload unexpectedly, resulting in a DOS condition. Exploitation requires no authentication and no user interaction.
