An attacker does not need to get through your firewall if they can simply turn it off.

CVE-2026-20349 — CVSS 8.6 — a single crafted HTTP request reloads Cisco Secure Firewall ASA and FTD appliances. Cisco published the advisory on August 11, 2026, already aware of exploitation in the wild. CISA gave federal agencies until August 14 to fix it.

WHAT ACTUALLY HAPPENED

The flaw is in how the Remote Access SSL VPN service processes HTTP requests. A remote, unauthenticated attacker sends one specially crafted request and the appliance reloads, dropping into a denial of service condition.

No credentials. No valid VPN account. No user interaction. If the device answers on that service, it is reachable.

Affected: ASA 9.16 through 9.24 and FTD 7.0 through 10.0, in every case where remote-access SSL VPN is enabled.

Cisco's PSIRT became aware of the attacks before a fix existed. This was a zero-day, not a patched bug someone weaponised months later.

Cisco is explicit that there are no workarounds. Upgrading is the only remediation.

WHY "ONLY A CRASH" CHANGES THE MATH

Denial of service bugs get triaged last. No data stolen, no code executed, nothing to write in a breach notification — so they slide down the risk register behind whatever has a 9.8 next to it.

Look at what actually reloads here. The VPN concentrator is the remote workforce, the site-to-site tunnels to your branches and partners, and very often the path your own responders use to reach the environment during an incident.

An attacker who can reload it on demand does not need persistence. They need a loop. The device comes back, takes the next request, and goes down again — indefinitely, from anywhere on the internet.

And when your remote access is down, so is your ability to investigate why.

WHAT TO DO NOW

UPGRADE — there is no configuration that mitigates this, so the fixed release is the only control that exists.

MAP WHAT DIES WITH THE VPN — list every process that depends on that appliance, including out-of-band admin access, and confirm you have a second way in that does not traverse it.

DISABLE RA SSL VPN WHERE IT IS NOT USED — plenty of appliances have the service enabled from an old deployment nobody revisited; if it is not serving users, it should not be listening.

TREAT UNEXPLAINED RELOADS AS AN INCIDENT — check crash dumps and syslog for reload events since early August, and stop filing them as instability.

Availability is a security property, not an operations problem. A control that can be switched off from the internet was never a control.

If your VPN concentrator went down and stayed down, how would your team reach production tonight?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.