Cisco ASA/FTD VPN flaw exploited for DoS
A remotely exploitable DoS vulnerability in Cisco ASA and Secure FTD VPN handling, CVE-2026-20349, is being actively exploited in the wild.
CERT-FR has issued an advisory regarding CVE-2026-20349, a vulnerability affecting Cisco Adaptive Security Appliance (ASA) and Secure Firepower Threat Defense (FTD) products. The flaw allows a remote, unauthenticated attacker to trigger a denial-of-service condition, and Cisco has confirmed active exploitation of the vulnerability in the wild.
Affected versions span multiple ASA release branches (9.16.x, 9.18.x, 9.20.x, 9.22.x, 9.23.x, and 9.24.x) lacking specific security patches, as well as Secure FTD deployments without the latest security fix. Cisco published bulletin cisco-sa-asaftd-vpn-dos-dzv4mQFF on August 11, 2026, detailing the issue and providing remediation guidance. Organizations running affected ASA or FTD versions, particularly those exposing VPN services, should prioritize patching given the confirmed active exploitation.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1010
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free