Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
Summary
Cisco has released a patch for a zero-day vulnerability (CVE-2026-20349) affecting its Secure Firewall ASA and FTD devices. This vulnerability has already been exploited in the wild to launch denial-of-service (DoS) attacks.
IFF Assessment
The exploitation of a zero-day vulnerability in widely used network devices represents a significant risk to organizations, enabling attackers to disrupt services.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.
Defender Context
This incident highlights the critical need for prompt patching of network infrastructure, especially firewalls, as zero-day vulnerabilities are actively exploited. Defenders should monitor for anomalous network traffic that could indicate DoS attacks targeting Cisco ASA and FTD devices and prioritize applying the vendor-supplied security updates.