(TLP:CLEAR) Vulnerability Notification – Cisco ASA and FTD Remote Access VPN DoS Actively Exploited
Created: Thursday, August 13, 2026 - 15:17
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) Software with Remote Access SSL VPN, IKEv2 Remote Access VPN (with client services), or Zero Trust Network Access (ZTNA) enabled. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: A high-severity denial-of-service (DOS) vulnerability affecting Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) Software is being actively exploited in the wild. Tracked as CVE-2026-20349 (CVSS 8.6), the vulnerability stems from insufficient error checking when the Remote Access SSL VPN service processes HTTP requests. Successful exploitation could allow an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload unexpectedly, resulting in a DOS condition. Exploitation requires no authentication and no user interaction.
Cisco’s Product Security Incident Response Team became aware of active exploitation in August 2026, though Cisco has not released details about the attackers, their origin, or which organizations have been targeted. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
Analyst Note: This vulnerability is particularly concerning for utilities because ASA and FTD appliances frequently sit directly on the network perimeter and provide remote access for operational personnel, administrators, contractors, and support systems. Because these remote-access services are commonly exposed to the internet by design, an attacker does not need to first compromise an internal system or obtain VPN credentials. A successful attack removes both the perimeter enforcement point and the remote access path at the same time, and repeated exploitation could interrupt VPN connectivity and disrupt access to systems supporting OT environments.
Cisco has released hotfixes and notes there are no workarounds that address the vulnerability. A device is affected only if it runs a vulnerable release and has at least one of the following configurations enabled: IKEv2 Remote Access VPN with client services, SSL VPN (webvpn), or ZTNA (FTD only). Cisco has confirmed that Secure Firewall Management Center (FMC) Software is not affected.
Affected Versions:
- Cisco Secure Firewall ASA Software 9.16 – upgrade to hotfix 89.16.4.50 (install ASDM Release 7.24.1.374, as earlier ASDM releases do not recognize the 89.x numbering format)
- Cisco Secure Firewall ASA Software 9.18 – upgrade to hotfix 89.18.4.50 (install ASDM Release 7.24.1.374, as earlier ASDM releases do not recognize the 89.x numbering format)
- Cisco Secure Firewall ASA Software 9.20 – upgrade to hotfix 9.20.4.235
- Cisco Secure Firewall ASA Software 9.22 – upgrade to hotfix 9.22.3.191
- Cisco Secure Firewall ASA Software 9.23 – upgrade to hotfix 9.23.1.211
- Cisco Secure Firewall ASA Software 9.24 – upgrade to hotfix 9.24.1.221
- Cisco Secure FTD Software 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 – branch-specific and platform-specific hotfix bundles are available; because the correct package depends on the FTD release and hardware platform, use Cisco’s advisory and Software Checker to identify the appropriate update for each device.
WaterISAC strongly encourages members to review Cisco’s advisory, determine whether any ASA or FTD appliance is running a vulnerable release with an affected VPN configuration enabled, and upgrade affected systems immediately using Cisco’s Software Checker to confirm the correct hotfix for each platform.
Original Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
Additional Reading:
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
- Cisco Says Software Vulnerability Could Let Hackers Crash Firewalls
Related WaterISAC PIRs: 6, 7, 8, 12
