Threat actors have already begun exploiting the flaw, according to the U.S. government.
Hackers could exploit a vulnerability in Cisco firewalls’ software to crash the devices, the networking giant is warning customers.
The flaw, tracked as CVE-2026-20349, “could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition,”<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF" rel="nofollow noopener" target=”_blank”>Cisco said in a Tuesday advisory.
Devices running two Cisco operating systems, Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD), are vulnerable toCVE-2026-20349, which stems from the software’s failure to properly check for errors when processing HTTP requests. Hackers could take advantage of that failure by sending error-riddled HTTP requests to the firewalls through their remote-access connections.
Cisco released fixes for multiple versions of the ASA and FTD software and said it “strongly recommends” that customers upgrade to those versions.
The Cybersecurity and Infrastructure Security Agency (CISA) immediatelyadded the flawto its Known Exploited Vulnerabilities catalog, indicating that hackers have quickly begun to take advantage of the flaw to target Cisco networking devices. Federal agencies have until Aug. 14 to upgrade affected devices.
Cisco devices have faceda wide range of cyberattacksin recent years, with the ASA and FTD operating systems producingrepeated vulnerabilities.
In September 2025, CISAissued an emergency directivewarning agencies to patchhigh-severity bugs in Cisco devicesrunning ASA. A U.S. official said at the time that the highly sophisticated campaign had already compromised at least 10 organizations around the world, and nearly 50,000 devices wererevealed to be vulnerable. The incidentprompted questionsfrom lawmakers about how seriously Cisco, a market leader in networking devices, was taking its products’ cybersecurity.
Filed Under:Vulnerability,Cyberattacks,Threats
