Affected Systems

Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled. Secure Firewall Management Center (FMC) is not affected.

Exploitation Status

Actively exploited in the wild since August 2026. No public PoC details disclosed. Attacker identity and targeted organizations unknown. Discovered through Cisco internal testing and independently reported by Valerio Brussani.

Business Impact

Remote unauthenticated attackers can crash ASA and FTD devices by sending crafted HTTP requests to VPN services, causing device reload and complete denial of service. This disrupts remote access VPN connectivity for users and may impact perimeter security posture. CVSS score 8.6 (high severity). No workarounds available. No indicators of compromise published by Cisco, limiting detection capabilities.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately inventory all Cisco ASA and FTD devices running versions 9.16-9.24 (ASA) or 7.0-10.0 (FTD) with VPN services enabled
  • Apply Cisco-provided hot fixes for affected ASA and FTD releases as priority patching—no workarounds exist
  • Monitor ASA and FTD device logs for unexpected reloads or HTTP request anomalies targeting SSL VPN services
  • Review VPN access logs for unusual connection patterns or failed authentication attempts preceding device crashes
  • Implement network-level rate limiting or access controls on VPN endpoints if patching cannot be completed immediately