Cisco Firewall Vulnerability Exploited in Active Attacks, CISA Warns
Cisco has disclosed a critical vulnerability (CVE-2026-20349) in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, which could allow unauthenticated attackers to trigger a denial-of-service (DoS) condition by crashing affected devices. The flaw stems from improper error handling in HTTP request processing, enabling hackers to exploit it via malformed remote-access connections.
The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. Federal agencies have until August 14 to patch affected systems. A U.S. official revealed that the campaign, described as highly sophisticated, has already compromised at least 10 organizations globally, with nearly 50,000 devices potentially at risk.
Cisco has released fixes for multiple ASA and FTD versions and urged customers to apply updates immediately. The company’s advisory follows growing scrutiny from lawmakers over its cybersecurity practices, given its dominance in networking infrastructure. The incident underscores the rapid weaponization of vulnerabilities, with threat actors leveraging the flaw within days of disclosure.
Source: https://www.cybersecuritydive.com/news/cisco-firewall-vulnerabilities-vpn-crash/827688/
Cisco TPRM report: https://www.rankiteo.com/company/cisco
Unknown Organizations TPRM report: https://www.rankiteo.com/company/unknowncyber
"id": "cisunk1786551853",
"linkid": "cisco, unknowncyber",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'At least 10 organizations '
'globally',
'industry': 'Technology/Networking',
'name': 'Cisco',
'type': 'Corporation'}],
'attack_vector': 'Malformed HTTP requests via remote-access connections',
'description': 'Cisco has disclosed a critical vulnerability (CVE-2026-20349) '
'in its Secure Firewall Adaptive Security Appliance (ASA) and '
'Secure Firewall Threat Defense (FTD) software, which could '
'allow unauthenticated attackers to trigger a '
'denial-of-service (DoS) condition by crashing affected '
'devices. The flaw stems from improper error handling in HTTP '
'request processing, enabling hackers to exploit it via '
'malformed remote-access connections. CISA confirmed active '
'exploitation, and the campaign has compromised at least 10 '
'organizations globally, with nearly 50,000 devices '
'potentially at risk.',
'impact': {'operational_impact': 'Device crashes leading to denial-of-service',
'systems_affected': 'Nearly 50,000 devices'},
'post_incident_analysis': {'root_causes': 'Improper error handling in HTTP '
'request processing'},
'recommendations': "Apply Cisco's patches immediately to mitigate the "
'vulnerability.',
'references': [{'source': 'CISA Known Exploited Vulnerabilities Catalog'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA added the '
'vulnerability to its '
'Known Exploited '
'Vulnerabilities (KEV) '
'catalog; federal '
'agencies must patch by '
'August 14'},
'response': {'remediation_measures': 'Cisco released patches for multiple ASA '
'and FTD versions'},
'title': 'Cisco Firewall Vulnerability Exploited in Active Attacks',
'type': 'Denial-of-Service (DoS)',
'vulnerability_exploited': 'CVE-2026-20349'}