Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Summary

Cisco has released a patch for a zero-day vulnerability (CVE-2026-20349) affecting its Secure Firewall ASA and FTD devices. This vulnerability has already been exploited in the wild to launch denial-of-service (DoS) attacks.

IFF Assessment

FOE

The exploitation of a zero-day vulnerability in widely used network devices represents a significant risk to organizations, enabling attackers to disrupt services.

Severity

8.6 High

CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.

Defender Context

This incident highlights the critical need for prompt patching of network infrastructure, especially firewalls, as zero-day vulnerabilities are actively exploited. Defenders should monitor for anomalous network traffic that could indicate DoS attacks targeting Cisco ASA and FTD devices and prioritize applying the vendor-supplied security updates.

Read Full Story →