Knox CVE Database
/
CVE-2026-20349
High
8.6

CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Added to the CISA KEV catalog:
August 11, 2026

Overview

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Vulnerability details

Affected vendor
Cisco
Affected product
Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Weakness type (CWE)
CWE-244

CVE-2026-20349 affects the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD software. The service performs insufficient error checking when processing inbound HTTP requests, a condition classified under CWE-244 involving improper heap memory handling. When a malformed request triggers an unhandled error path, the device reloads unexpectedly. The flaw is present only when one or more SSL listen sockets are active: IKEv2 Remote Access VPN with client services, SSL VPN (webvpn), or Zero Trust Network Access (FTD only).


An unauthenticated remote attacker sends a crafted HTTP request to the exposed Remote Access SSL VPN service. No credentials or prior session are required. A successful request causes the firewall to reload, dropping all active VPN sessions and interrupting all traffic the device handles. Because the service is typically internet-facing, the attack surface is broad for any organization running a vulnerable ASA or FTD release with one of the three vulnerable configurations active. Cisco states there are no workarounds; patching is the only remediation.

Severity and impact

8.6
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
None
Integrity impact
None
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor ASA and FTD syslog output for unexpected reload or crash events (system restart messages, traceback logs) that are not preceded by a scheduled maintenance window or administrator-initiated reload command, particularly when the device is running a vulnerable release with SSL VPN exposed.
  • Correlate firewall reload events against SSL VPN connection logs: a reload with no matching administrator action and a spike in inbound HTTP requests to the VPN listener immediately before the event is a strong indicator of exploitation attempts.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 14, 2026

Additional hardening

  • Apply the Cisco-released hot fixes: for ASA, the applicable hot fix per release train is listed in the vendor advisory; for FTD 7.0, apply hotfix GC-7.0.9.1-1, and for FTD 7.2, apply hotfix HM-7.2.11.1-2. See References for the full advisory.
  • Restrict access to the Remote Access SSL VPN listener to known IP ranges using access control lists or an upstream firewall, reducing exposure to unauthenticated internet sources that could send crafted requests.
  • If the SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access feature is not operationally required on a given interface, disable it to remove the vulnerable listen socket entirely.
  • Place affected devices behind a network-layer control (such as a load balancer or upstream filtering device) that can rate-limit or block malformed HTTP requests to the VPN service port while patching is in progress.

Key dates

Published (NVD)
August 11, 2026
Added to CISA KEV
August 11, 2026
Remediation deadline
August 14, 2026
Last updated
August 12, 2026

References

Frequently asked questions

Does CVE-2026-20349 affect my FedRAMP authorization?

If Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) runs inside your authorization boundary, CVE-2026-20349 does affect your FedRAMP authorization. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 14, 2026. An unpatched KEV inside your boundary is an assessor finding. You must remediate it or formally document a mitigation before your assessor or sponsoring agency raises it.

How does Knox help me handle CVE-2026-20349?

Knox does not patch your software. Remediating Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including cases like CVE-2026-20349. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team earlier visibility and more time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-20349 isn't remediated by August 14, 2026?

Missing the August 14, 2026 deadline turns CVE-2026-20349 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting