CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Summary

Cisco Secure Firewall ASA and FTD devices have a heap inspection vulnerability that could allow remote attackers to cause a denial of service. Cisco advises applying mitigations and following CISA's guidance for prioritizing security updates.

IFF Assessment

FOE

This vulnerability could allow an unauthenticated, remote attacker to cause a denial of service, impacting the availability of critical network security devices.

Severity

8.6 High

CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Cisco Secure Firewall devices presents a significant risk of denial of service for organizations relying on these products for network security. Defenders should prioritize applying vendor-provided mitigations and follow CISA's directives for risk-based patching, especially for internet-facing assets.

Read Full Story →