Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
Summary
Cisco has issued a warning about a high-severity vulnerability in its Secure Firewall ASA and FTD software, which has already been exploited in the wild. The flaw, tracked as CVE-2026-20349, allows unauthenticated remote attackers to trigger a denial-of-service (DoS) condition due to insufficient error checking when processing HTTP requests.
IFF Assessment
This vulnerability allows remote attackers to cause a denial-of-service, impacting the availability of critical network infrastructure.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability poses a significant risk to organizations using Cisco ASA and FTD devices, as it can lead to service disruptions. Defenders should prioritize patching these devices immediately to prevent exploitation and monitor their networks for any signs of DoS activity. The fact that it's being exploited in the wild underscores the urgency of applying the available security updates.