Security Advisory Desk
highQCS priority 100/100Cisco

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

A security flaw exists in Cisco Secure Firewall devices that use the Remote Access SSL VPN service. This flaw lets an attacker who is not logged in send a special message that causes the device to restart unexpectedly, leading to service interruptions. Cisco has released updates that fix this issue, but no temporary solutions are available.

Published 11/8/2026, 4:39:00 pmVerified 11/8/2026, 5:10:42 pmRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

A security flaw exists in Cisco Secure Firewall devices that use the Remote Access SSL VPN service. This flaw lets an attacker who is not logged in send a special message that causes the device to restart unexpectedly, leading to service interruptions. Cisco has released updates that fix this issue, but no temporary solutions are available.

Technical explanation

How the issue affects the environment

The vulnerability is due to insufficient error checking of HTTP requests processed by the Remote Access SSL VPN service on Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests to the affected SSL VPN service. Successful exploitation causes the device to reload unexpectedly, resulting in a denial of service (DoS). This vulnerability is identified as CVE-2026-20349 with a high severity rating and CVSS base score of 8.6. It affects configurations where Remote Access VPN or Zero Trust Network Access features enable SSL VPN listening sockets. Cisco has released hotfixes and software updates addressing the vulnerability across multiple software releases.

Operational impact

Why teams should care

Exploiting this vulnerability disrupts the operation of Cisco Secure Firewall devices by causing unexpected reloads. This leads to denial of service conditions, potentially interrupting network security enforcement and remote user connectivity. Businesses relying on these services may experience downtime and reduced security posture until the vulnerability is remediated with updated software.

Immediate action

Cisco strongly recommends upgrading affected Cisco Secure Firewall ASA and FTD software to the released fixed versions containing hotfixes addressing this vulnerability. Customers should download and install these updates from Cisco's Software Center to fully remediate the issue and prevent denial of service attacks. Following the upgrade guide is advised to ensure proper installation.

Affected and fixed releases

Affected versionsThe advisory does not specify precise affected software versions but indicates multiple Cisco Secure Firewall ASA and FTD Software releases with Remote Access SSL VPN enabled are,, including those supporting features like IKEv2 Remote Access VPN with client services and Zero Trust Network Access.
Fixed versionsCisco Secure Firewall ASA Software hotfixes: 9.16.1 (89.16.4.50), 9.18.1 (89.18.4.50), 9.20 (9.20.4.235), 9.22 (9.22.3.191), 9.23 (9.23.1.211), 9.24 (9.24.1.221), Cisco Secure FTD Software hotfixes for releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 listed by specific hotfix package names as per Cisco advisory.

Temporary risk reduction

There are no workarounds available for this vulnerability as stated by Cisco. The only effective mitigation is to apply the released software updates.

Evidence and validation checklist

  • Cisco Security Advisory published August 11, 2026 at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
  • Description of vulnerability involving insufficient error checking in Remote Access SSL VPN service causing device reload and DoS.
  • Identification of affected products and configurations involving Cisco Secure Firewall ASA and FTD software with Remote Access VPN features enabled.
  • Cisco's statement that no workaround exists and recommendation to upgrade to fixed software releases.
  • Details of fixed software versions and hotfix names for multiple ASA and FTD releases.
  • Notification of active exploitation and high severity rating (CVSS 8.6).

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco Secure Firewall Adaptive Security | Advisory | QCS