Affected Systems
Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled. Only devices with these specific VPN/remote access configurations are vulnerable.
Exploitation Status
Active exploitation confirmed in the wild. Cisco became aware of exploitation in early August 2026. No details on threat actor identity, targets, or attack success disclosed. CISA added CVE-2026-20349 to KEV catalog.
Business Impact
Unauthenticated remote attackers can crash vulnerable ASA/FTD devices via crafted HTTP requests to VPN services, causing complete device reload and network outage. Critical for organizations relying on Cisco firewalls for perimeter security and remote access. No workarounds available—patching is mandatory. Federal agencies face August 14, 2026 compliance deadline.
Urgency
🔴 Immediate
Recommended Actions
- Immediately inventory all Cisco ASA and FTD devices to identify vulnerable versions (ASA 9.16.1–9.24, FTD 7.0–10.0) with IKEv2, SSL-VPN, or Zero Trust enabled
- Apply Cisco-provided hotfixes or upgrade to fixed versions: ASA 9.16.4.50+, 9.18.4.50+, 9.20.4.235+, 9.22.3.191+, 9.23.1.211+, 9.24.1.221+; FTD hotfixes per version (e.g., GC-7.0.9.1-1, HM-7.2.11.1-2, HK-7.4.7.1-1, DD-7.6.4.1-2, AN-7.7.11.1-2, S-10.0.0.1-2)
- Monitor firewall logs for unexpected device reloads, HTTP request anomalies to VPN services, and failed connection attempts during business hours
- Implement network-layer rate limiting or IP allowlisting on VPN interfaces if patching requires extended maintenance windows
- Verify patch deployment success by confirming software version post-update and testing VPN service availability
