Cisco Issues Emergency Fix for Firewall Zero-Day Under Active Attack

Cartoon of firewall SSL VPN under attack

Cisco has issued an urgent warning to organizations worldwide following the discovery of a zero-day vulnerability in its core firewall software. Tracked as CVE-2026-20349, the flaw is currently being exploited in the wild, allowing unauthenticated attackers to trigger a denial-of-service (DoS) condition. Because this vulnerability affects the perimeter of the network—the very place designed to keep threats out—security teams are being urged to prioritize patching immediately.

The Nature of the Zero-Day Flaw

The vulnerability exists within the Remote Access SSL VPN service of two major Cisco platforms: the Secure Firewall Adaptive Security Appliance (ASA) and the Secure Firewall Threat Defense (FTD). At its core, the issue stems from insufficient error checking when the SSL VPN service processes incoming HTTP requests.

A remote attacker does not need valid credentials or any special privileges to exploit this. By simply sending a specifically crafted HTTP request to an exposed device, the attacker can force the appliance to reload unexpectedly. This sudden reboot disconnects all active VPN sessions and halts any network traffic that relies on the firewall, effectively cutting off remote workers and disrupting site-to-site connectivity.

Who is at Risk

Not every Cisco firewall is vulnerable. For a device to be at risk, it must be running an affected version of ASA or FTD software and have specific features enabled that open SSL listening sockets. These include:

SSL VPN with WebVPN enabled on an interface.

IKEv2 Remote Access VPN with client services enabled.

Zero Trust Network Access (ZTNA) on FTD devices when the feature is active.

Cisco has clarified that the Secure Firewall Management Center (FMC) is not impacted by this specific flaw. Administrators should immediately audit their configurations to see if these services are running on internet-facing interfaces.

The Race to Patch

The exploitation was first detected in August 2026, and Cisco’s Product Security Incident Response Team (PSIRT) has confirmed that there are no manual workarounds to mitigate the risk. The only way to secure the perimeter is to apply the official software updates or hotfixes provided by Cisco.

Cisco has released hotfixes for a wide range of software branches, including ASA 9.16 through 9.24 and FTD 7.0 through 10.0. For those managing ASA devices, Cisco notes that specific ASDM releases (7.24.1.374 or later) may be required to recognize the new hotfix numbering format correctly.

A Reminder of Perimeter Vulnerability

This incident serves as a stark reminder that VPN gateways and edge firewalls remain high-value targets for threat actors. Because these devices sit directly on the internet, any unauthenticated bug can be leveraged quickly to cause widespread operational disruption. Organizations using Cisco’s security stack should treat this as a high-priority event, moving to validated software versions before attackers can further disrupt their business operations.

Leave a Reply

Your email address will not be published. Required fields are marked *