Your firewall does not need to be breached to take you offline

It just needs to be rebooted — remotely, unauthenticated, on repeat.

CVE-2026-20349 is an actively exploited flaw in the VPN web server of Cisco Secure Firewall ASA and FTD. CVSS 8.6. One crafted HTTP request to the Remote Access SSL VPN service forces the device to reload. Cisco PSIRT confirmed in-the-wild exploitation on August 11; CISA set a federal remediation deadline of August 14.

WHAT ACTUALLY HAPPENED

The root cause is insufficient error checking while processing HTTP requests. No credentials required, no user interaction, no foothold needed. Affected devices are those running ASA or FTD with remote-access services enabled: SSL VPN, IKEv2 remote access VPN with client services, or Zero Trust Network Access on FTD.

Cisco published fixed releases per train in advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF. There is no workaround that keeps remote access VPN running — the mitigation is the patch.

WHY A DOS ON THE VPN HEAD-END IS NOT "JUST" A DOS

Security teams instinctively rank denial of service below remote code execution. On a VPN concentrator that ranking is wrong.

The ASA is the front door for your remote workforce, your site-to-site tunnels, and often your out-of-band administrative access. Knock it down and you have not merely dropped sessions — you have removed the path your engineers use to fix things, and potentially the path your monitoring uses to see things. A repeatable unauthenticated reload is an availability weapon and a cover-your-tracks tool at the same time.

WHAT TO DO NOW

INVENTORY BY FEATURE, NOT BY MODEL — exposure depends on whether SSL VPN, IKEv2 with client services, or ZTNA is enabled, so audit the running config rather than the hardware list.

PATCH TO THE FIXED TRAIN THIS WEEK — the federal deadline has already passed and exploitation is confirmed; an unpatched internet-facing head-end is a live target.

VERIFY YOU HAVE OUT-OF-BAND ACCESS — if your only route to the firewall is through the firewall, a reload loop turns a patchable bug into an on-site truck roll.

ALERT ON UNEXPLAINED RELOADS — repeated ASA/FTD restarts with no change ticket behind them are the primary detection signal here.

Availability is a security property. The bug that only "crashes" your edge is still the bug that decides whether you can respond to the next one.

Do you have a way into your perimeter devices that does not depend on those devices being up?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.