CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Summary
Cisco Secure Firewall ASA and FTD devices have a heap inspection vulnerability that could allow remote attackers to cause a denial of service. Cisco advises applying mitigations and following CISA's guidance for prioritizing security updates.
IFF Assessment
This vulnerability could allow an unauthenticated, remote attacker to cause a denial of service, impacting the availability of critical network security devices.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Cisco Secure Firewall devices presents a significant risk of denial of service for organizations relying on these products for network security. Defenders should prioritize applying vendor-provided mitigations and follow CISA's directives for risk-based patching, especially for internet-facing assets.