LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 11, 2026
CVSS 8.6 · High⚠ Actively exploited (CISA KEV)
8.6
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 14, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on Aug 11, 2026, with a federal patch deadline of Aug 14, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

CVE-2026-20349 is a heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). According to CISA, an unauthenticated remote attacker could trigger an unexpected device reload and cause a denial of service. Firewalls in this class often sit at network edges, so availability loss can interrupt traffic inspection, VPN, and segmentation controls until the device recovers. Confirm exact product lines, fixed releases, and any configuration prerequisites only against the vendor advisory.

There is no documentation in the provided facts that this issue has been used in ransomware campaigns. Treat it as a serious availability risk for internet-facing or otherwise reachable ASA/FTD deployments and prioritize accordingly under your change and risk processes, including any applicable CISA BOD 26-04 obligations.

How it works

The weakness is tracked as CWE-244 (improper clearing of heap memory before release, often discussed as heap inspection). In general, this class involves residual or inspectable heap state that software does not clear as intended. The CISA summary for this CVE states the practical outcome on affected Cisco ASA and FTD software: an unauthenticated, remote attacker may cause the device to reload unexpectedly, producing a denial-of-service condition.

Public detail in the facts does not describe packet formats, specific interfaces, or step-by-step exploit mechanics. Defenders should assume that reachability to a vulnerable service or path on the appliance is enough for an unauthenticated remote party to attempt to induce the reload, and should not rely on authentication alone as a barrier. Do not invent or test exploit procedures; use vendor and CISA guidance for impact and scope.

Am I affected? How to find it in your systems

Cisco ASA and FTD commonly run as physical appliances, virtual firewalls, or cloud-delivered firewall instances enforcing perimeter, DC, branch, or segmentation policy. Inventory every ASA and FTD instance: management systems (for example Cisco management platforms you already use), configuration databases, CMDB entries, network diagrams, and authenticated CLI or API show commands that report software identity and version. Compare those versions and any stated vulnerable configurations only to the Cisco advisory for CVE-2026-20349; this record does not list version numbers.

Evaluate internet exposure and other untrusted reachability for each asset, as CISA notes stakeholders must do under BOD 26-04-style prioritization. For exploitation signs, watch for unexplained reloads, crash or core-related logs, sudden HA failovers, interface or tunnel flaps correlated with reloads, and spikes in unreachable or degraded firewall health telemetry. Such signals are not proof of this CVE alone; correlate with change windows and vendor diagnostic guidance. If you suspect compromise beyond a simple DoS, follow your incident process and any CISA forensics triage requirements referenced in the advisory notes.

How to remediate

Patch first: apply the Cisco-supplied update or fixed software train named in the vendor advisory for CVE-2026-20349. Schedule maintenance with HA or hitless strategies your platform supports so reloads during upgrade are controlled. After upgrade, verify the running image matches the fixed release and that traffic and high-availability state are healthy.

Then harden for this product and weakness class: reduce untrusted exposure to management and data-plane services that are not required; enforce management-plane ACLs and out-of-band administration; keep secure baseline configs; and ensure logging and monitoring cover reload and health events. Apply mitigations exactly as Cisco documents; if mitigations are unavailable for a given deployment model, CISA’s required action language includes following BOD 26-04 guidance for cloud services or discontinuing use when appropriate. Confirm every version and mitigation string against the vendor advisory rather than secondary summaries.

If you can't patch immediately

Until the vendor fix is installed, lower likelihood and impact with compensating controls suited to edge firewalls:

CISA directs applying mitigations per vendor instructions and BOD 26-04 risk-based prioritization, including exposure evaluation. Reassess daily until patched.

If your data may have been exposed

The facts describe a denial-of-service condition via unexpected reload, not a confirmed data-theft primitive, and known ransomware use is not documented here. Actively exploited firewall vulnerabilities can still coincide with broader intrusions or follow-on abuse in real incidents, so treat unexplained reloads on exposed devices as investigation triggers: preserve logs, validate integrity of configs and images, and follow CISA forensics triage expectations where they apply. If you believe credentials or identities may have been involved in a wider event, rotate secrets that traversed the device and review adjacent systems. You can also run a free exposure scan of your email addresses against known breach datasets to see whether those identities already appear in public breach collections, which is a separate check from this CVE’s DoS impact.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
WeaknessCWE-244
CVSS base score8.6 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
PublishedAug 11, 2026
Added to CISA KEVAug 11, 2026
Federal patch deadlineAug 14, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities