In plain language
What this advisory means
A flaw in Cisco Secure Firewall ASA and Threat Defense software's SSL VPN function allows attackers to crash devices remotely, causing denial of service. Attackers send crafted HTTP requests to trigger reloads, disrupting network security. Cisco has released updates to fix this issue, but no temporary workaround exists.
Technical explanation
How the issue affects the environment
The vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software affects the Remote Access SSL VPN service. It arises from insufficient HTTP request error validation, enabling unauthenticated remote attackers to send crafted HTTP requests that cause the devices to reload unexpectedly. This leads to a denial of service by interrupting the firewall's operation. The affected configurations include IKEv2 Remote Access VPN, SSL VPN, and Zero Trust Network Access features that enable SSL listening sockets. Cisco has released software updates in specific versions to address this issue; no workarounds mitigate the risk.
Operational impact
Why teams should care
Exploitation results in network security devices unexpectedly rebooting, leading to denial of service. This disrupts firewall protection, potentially exposing networks to additional threats and causing interruptions in business operations relying on secure VPN access channels.
Immediate action
Upgrade to the Cisco software releases that include the fix for this vulnerability as detailed in the advisory to remediate the issue. Cisco strongly recommends this upgrade since no workarounds exist.
Affected and fixed releases
Temporary risk reduction
Cisco reports no workarounds address this vulnerability; upgrading the software is the only effective remediation.
Evidence and validation checklist
- Official Cisco Security Advisory (cisco-sa-asaftd-vpn-dos-dzv4mQFF)
- Cisco CVE entry for CVE-2026-20349
- Cisco software fixed release tables
- Cisco PSIRT confirmation of active exploitation
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
