Exploited in the wild Cisco Secure Firewall ASA network-edge Cisco Secure Firewall Threat Defense (FTD) Cisco zero-day
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
CVE Tools coverage
Cisco has released hot fixes for CVE-2026-20349, a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software that is currently being actively exploited to crash devices. The flaw, which stems from insufficient error handling of HTTP requests, allows attackers to remotely trigger a device reload without authentication or user interaction when specific remote access services like SSL VPN are enabled. Affected products include ASA versions 9.16 through 9.24 and FTD releases 7.0 through 10.0, though Secure Firewall Management Center remains unaffected. Since there are no workarounds, administrators should immediately upgrade their systems to the patched releases provided by Cisco.