A firewall that keeps rebooting under a targeted attack is not a theoretical risk. It is a live availability incident, and Cisco has confirmed one is already happening against its most widely deployed VPN edge devices.
The flaw and who is already using it
CVE-2026-20349 sits in how Cisco Secure Firewall ASA and Secure Firewall FTD software handle HTTP requests sent to the Remote Access SSL VPN service. Cisco describes it as improper disposal of heap-allocated memory before release, and the practical effect is blunt: a remote, unauthenticated attacker sends one specially crafted HTTP request, and the appliance reloads. No credentials, no prior access, no user interaction. Cisco rates it 8.6 out of 10 and, unusually, disclosed it already under active exploitation rather than ahead of it. CISA added CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on the same day the advisory went out, 11 August, which under the federal directive gives affected US agencies a fixed patching deadline. European organisations running the same devices do not get that deadline handed to them, but they are exposed to exactly the same crafted request.
Which devices are actually at risk
The flaw only affects ASA or FTD deployments that have at least one of three features enabled: IKEv2 Remote Access VPN with client services, SSL VPN, or Zero Trust Network Access. That is a large share of production firewalls, since remote access VPN is precisely the feature most organisations turned these appliances on for in the first place. Cisco has published hotfixes for the actively used release trains, 9.16 and 9.18, along with a fixed build on the 9.14 line, all available through the Cisco Software Center. There is no configuration-only mitigation that closes the hole; restricting Remote Access SSL VPN reachability to known source ranges and deploying the Snort detection rules Cisco has published reduce exposure while a patch is scheduled, but they do not replace the fix.
Why a denial-of-service bug still deserves urgent treatment
It is tempting to rank a reload bug below a full remote code execution flaw, and in isolation that instinct is not wrong. But a firewall that an attacker can reliably crash on demand is a firewall an attacker can use to force failover, mask other activity behind the resulting outage, or simply take a VPN gateway offline for every remote worker and site-to-site tunnel that depends on it. For organisations under NIS2 or DORA obligations, an unplanned outage of the device that terminates remote access is itself a reportable availability event if it crosses the relevant threshold, independent of whether any data was actually taken.
What to check this week
Confirm whether your ASA or FTD estate has Remote Access SSL VPN, IKEv2 client services, or ZTNA enabled, then apply the relevant hotfix or fixed release rather than waiting for the next scheduled maintenance window. If patching cannot happen immediately, restrict VPN termination interfaces to expected source ranges and deploy the published Snort rules as an interim control.
If your organisation runs Cisco ASA or Secure Firewall and needs help confirming exposure to CVE-2026-20349, getting the hotfix deployed without disrupting active VPN users, or reviewing whether your incident reporting obligations under NIS2 or DORA are triggered by an outage like this one, contact Excello Digital. We help European teams turn an actively exploited advisory into a same-week fix.
