Cisco VPN Flaw Actively Crashes Devices
TL;DR. Cisco reports active exploitation of a high-severity denial-of-service vulnerability in its Secure Firewall ASA and FTD software. - The flaw, CVE-2026-20349, allows remote attackers to crash affected devices without authentication. - Cisco has released hot fixes for various ASA and FTD software versions and urges immediate upgrades. - Details on attackers or targeted organizations remain undisclosed, with no available workarounds.
- Cisco identified CVE-2026-20349, a high-severity DoS flaw in Secure Firewall ASA/FTD.
- The vulnerability is actively exploited to remotely crash VPN devices.
- Hot fixes are available; Cisco recommends immediate software upgrades.
Sources
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices — bleepingcomputer.com