{"id":502,"date":"2026-08-17T12:59:28","date_gmt":"2026-08-17T07:29:28","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=502"},"modified":"2026-08-18T14:41:03","modified_gmt":"2026-08-18T09:11:03","slug":"cve-2026-20349-cisco-asa-ftd-vpn-flaw","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/","title":{"rendered":"CVE-2026-20349: Cisco ASA and FTD VPN Flaw Exploited in the Wild"},"content":{"rendered":"<p>Cisco ASA and FTD administrators have another actively exploited edge-device vulnerability to address. CVE-2026-20349 is a high-severity denial-of-service (DoS) vulnerability. It affects remote-access functionality in Cisco Secure Firewall ASA and FTD software.<\/p>\n<p>Remote attackers can exploit the vulnerability without authentication. An attacker can send a crafted HTTP request to an affected service. The request can cause the device to reload. A successful attack can interrupt VPN connectivity and other remote-access operations.<\/p>\n<p>Cisco has confirmed exploitation in the wild. For everyone else, the more important point is simpler: exploitation is no longer hypothetical, there is no workaround, and affected deployments need Cisco&#8217;s fixed software.<\/p>\n<h2>Key Facts About CVE-2026-20349<\/h2>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Field<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">CVE<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-20349<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Severity<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">CVSS 8.6 (High)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Attack requirements<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Remote, unauthenticated, no user interaction<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Impact<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Denial of service resulting in device reload<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Remote code execution<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not reported<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Exploitation status<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Active exploitation confirmed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">CISA KEV<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Listed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Federal remediation deadline<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">August 14, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Workaround<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">None<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Affected services<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, Zero Trust Network Access (applicable FTD configurations)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not affected<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Cisco Secure Firewall Management Center (FMC)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What Changed: CVE-2026-20349 Is Now an Active Exploitation Issue<\/h2>\n<p>The most important development around CVE-2026-20349 is Cisco&#8217;s confirmation of active exploitation. Attackers are already exploiting the vulnerability in the wild. That confirmation gives defenders a concrete prioritization signal. Organizations should no longer treat exploitation as a theoretical risk.<\/p>\n<p>For U.S. federal civilian executive branch agencies, the listing comes with an August 14, 2026 remediation deadline. The deadline does not apply to private-sector organizations. However, the exploitation signal remains relevant to organizations running affected Cisco infrastructure.<\/p>\n<p>That distinction matters. Vulnerability management teams routinely face more high-severity vulnerabilities than they can patch immediately.<\/p>\n<p>Several factors increase the vulnerability&#8217;s remediation priority:<\/p>\n<ul>\n<li>Confirmed exploitation<\/li>\n<li>Internet accessibility<\/li>\n<li>No authentication requirement<\/li>\n<li>No available workaround<\/li>\n<\/ul>\n<h2>How CVE-2026-20349 Works<\/h2>\n<p>CVE-2026-20349 affects HTTP request processing tied to certain remote-access services in Cisco ASA and FTD.<\/p>\n<p>Cisco attributes the vulnerability to insufficient error checking while processing HTTP requests. A crafted request can trigger a failure condition that causes an affected device to reload.<\/p>\n<p>An attacker doesn&#8217;t need valid VPN credentials or an authenticated session to reach the vulnerable condition. If the relevant service is reachable, a crafted HTTP request can trigger the flaw and cause the device to reload.<\/p>\n<table style=\"font-weight: 400; width: 96.0175%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"4\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 44.5748%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Security property<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 221.408%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Reported impact<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 44.5748%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Confidentiality<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 221.408%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No reported impact<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 44.5748%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Integrity<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 221.408%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No reported impact<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 44.5748%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Availability<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 221.408%;\" data-celllook=\"0\"><span data-contrast=\"auto\">High: device reload\/DoS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This boundary matters. Cisco does not currently report remote code execution as an impact of CVE-2026-20349. Cisco hasn&#8217;t reported credential theft, authentication bypass, <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-privilege-escalation\/\">privilege escalation<\/a>, or data theft as consequences of exploiting this flaw.<\/p>\n<p>That does not make the vulnerability trivial. It changes the nature of the risk. Instead of taking control of the appliance, an attacker can interfere with its ability to stay available.<\/p>\n<h3>Which Cisco Services Are Exposed?<\/h3>\n<p>The vulnerability only matters where affected software and vulnerable functionality intersect. Running Cisco ASA or FTD doesn&#8217;t, by itself, mean a given appliance exposes the vulnerable attack surface.<\/p>\n<p>Cisco identifies affected configurations involving:<\/p>\n<ul>\n<li>Remote Access SSL VPN<\/li>\n<li>IKEv2 Remote Access VPN with client services<\/li>\n<li>Zero Trust Network Access, on applicable FTD deployments<\/li>\n<\/ul>\n<p>Cisco Secure Firewall Management Center (FMC) is not affected. Although FMC can manage FTD remote-access VPN configurations, the vulnerability affects the ASA and FTD software that exposes the vulnerable services.<\/p>\n<table style=\"font-weight: 400; width: 99.7491%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"10\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Product or service<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE-2026-20349 status<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Cisco Secure Firewall ASA<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected on vulnerable releases\/configurations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Cisco Secure Firewall FTD<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected on vulnerable releases\/configurations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Remote Access SSL VPN<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">IKEv2 Remote Access VPN with client services<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Zero Trust Network Access<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected on applicable FTD configurations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Secure Firewall Management Center<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Not affected<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Authentication required<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">User interaction\u00a0required<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 49.3392%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Workaround available<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 88.1057%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>For administrators, exposure assessment should weigh both software version and configuration.<\/p>\n<p>Prioritize internet-reachable appliances that run affected releases and expose vulnerable remote-access functionality. Appliances without exposed vulnerable services carry a different level of immediate risk.<\/p>\n<h2>No Workaround: What Administrators Need to Patch<\/h2>\n<p>Cisco hasn&#8217;t provided a workaround that fully mitigates CVE-2026-20349. The remediation path is to move affected systems to fixed software.<\/p>\n<p>Hot fixes are available across affected release trains:<\/p>\n<ul>\n<li><strong>ASA<\/strong>: 9.16, 9.18, 9.20, 9.22, 9.23, 9.24<\/li>\n<li><strong>FTD<\/strong>: 7.0, 7.2, 7.4, 7.6, 7.7, 10.0<\/li>\n<\/ul>\n<p>Administrators should consult <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-vpn-dos-dzv4mQFF?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Remote%20Access%20SSL%20VPN%20Denial%20of%20Service%20Vulnerability%26vs_k=1?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=cve_2026_20349\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Cisco&#8217;s current advisory<\/a> to identify the correct fixed release or hot fix. Do not rely on the release train alone.<\/p>\n<p>There&#8217;s also an operational consideration for some older ASA deployments. Administrators applying an ASA hot fix whose name begins with 89 should install ASDM 7.24.1.374, because earlier ASDM releases do not recognize that ASA software release-numbering format.<\/p>\n<h3>What Organizations Should Do Now<\/h3>\n<ol>\n<li><strong>Inventory ASA and FTD infrastructure<\/strong>. Identify appliances that provide externally accessible remote-access services. Prioritize internet-facing systems.<\/li>\n<li><strong>Check software versions<\/strong>. Compare installed software with Cisco&#8217;s current advisory and fixed-release guidance.<\/li>\n<li><strong>Verify affected services<\/strong>. Check for SSL VPN, IKEv2 Remote Access VPN, and applicable FTD Zero Trust Network Access.<\/li>\n<li><strong>Apply Cisco&#8217;s fix<\/strong>. Install the relevant fixed software or hot fix. Prioritize exposed systems because attackers already exploit this vulnerability.<\/li>\n<li><strong>Validate services<\/strong>. Check VPN connectivity, authentication, device stability, management access, and monitoring after the update.<\/li>\n<li><strong>Investigate unexplained reloads<\/strong>. Review appliance telemetry for unexpected reloads or remote-access disruptions.<\/li>\n<\/ol>\n<h2>What Cisco Has Confirmed and What Remains Unknown<\/h2>\n<p>Active-exploitation disclosures often create a vacuum that quickly fills with assumptions about threat actors, campaigns, and victims. Keeping confirmed information separate from unknowns helps avoid turning limited evidence into unsupported attribution.<\/p>\n<h3>Confirmed:<\/h3>\n<ul>\n<li>CVE-2026-20349 carries a CVSS score of 8.6<\/li>\n<li>Remote exploitation doesn&#8217;t require authentication<\/li>\n<li>Successful exploitation can cause an affected device to reload<\/li>\n<li>Cisco has confirmed active exploitation of the vulnerability<\/li>\n<li>The vulnerability affects specific ASA and FTD remote-access configurations<\/li>\n<li>No workaround fully addresses the vulnerability<\/li>\n<li>Fixed software and hot fixes are available<\/li>\n<li>The vulnerability does not affect Secure Firewall Management Center<\/li>\n<\/ul>\n<h3>Not publicly known:<\/h3>\n<ul>\n<li>How widespread exploitation is<\/li>\n<li>Which threat actors are exploiting the vulnerability<\/li>\n<li>Whether exploitation involves one campaign or multiple actors<\/li>\n<li>Whether specific industries, organizations, or regions are being targeted<\/li>\n<li>Detailed indicators for identifying exploitation attempts<\/li>\n<\/ul>\n<p>Until Cisco, CISA, or credible security researchers disclose more, treat any claims about attribution, victim counts, or targeted sectors with caution.<\/p>\n<h2>Why a VPN Denial-of-Service Vulnerability Still Matters<\/h2>\n<p>CVE-2026-20349 doesn&#8217;t carry the kind of impact normally associated with an edge-device RCE. But focusing only on that distinction can underestimate the vulnerability&#8217;s operational significance.<\/p>\n<p>VPN infrastructure sits at a critical junction between users, administrators, and internal resources. Repeated device reloads can create several operational problems:<\/p>\n<ul>\n<li>Interrupt remote sessions<\/li>\n<li>Disrupt administrative access<\/li>\n<li>Reduce workforce connectivity<\/li>\n<li>Increase pressure on network and security teams<\/li>\n<\/ul>\n<p>There&#8217;s another wrinkle: the people responsible for responding to an incident may themselves depend on remote-access infrastructure.<\/p>\n<p>A VPN outage during another security incident can affect more than employee productivity. The outage can block responders from reaching internal systems and complicate their investigation.<\/p>\n<p>Availability is a security property for exactly this reason. The risk is especially relevant where three conditions overlap:<\/p>\n<p style=\"text-align: center;\"><strong>internet exposure + vulnerable remote-access functionality + unpatched software<\/strong><\/p>\n<p>CVE-2026-20349 also requires no authenticated account. An attacker doesn&#8217;t need to steal VPN credentials first to attempt exploitation against a reachable, vulnerable service.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Sonic-Wall-SMA1000-Zero-Day-Patch-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>SonicWall SMA1000 Zero-Day: Patch CVE-2026-15409 & CVE-2026-15410<\/h4><p>See how another actively exploited vulnerability affected enterprise VPN and remote-access infrastructure.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/sonicwall-sma1000-zero-day-cve-2026-15409-cve-2026-15410\/\" aria-label=\"SonicWall SMA1000 Zero-Day: Patch CVE-2026-15409 & CVE-2026-15410\"><\/a><\/div><\/div><\/div>\n<h2>What the KEV Listing Does and Doesn&#8217;t Tell Us<\/h2>\n<p>CISA&#8217;s KEV catalog identifies vulnerabilities with evidence of active exploitation that meet CISA&#8217;s criteria for catalog inclusion.<\/p>\n<p>Cisco&#8217;s confirmation establishes a critical fact. Attackers have exploited CVE-2026-20349 in real-world environments.<\/p>\n<p>It does not tell us:<\/p>\n<ol>\n<li>How many attackers are involved<\/li>\n<li>How many organizations have been targeted<\/li>\n<li>Whether exploitation is widespread<\/li>\n<li>Whether exploitation is opportunistic or targeted<\/li>\n<li>Whether CISA expects a specific future campaign<\/li>\n<\/ol>\n<p>The practical takeaway isn&#8217;t that every Cisco ASA or FTD appliance is under attack. It&#8217;s that patch prioritization should no longer assume exploitation is hypothetical.<\/p>\n<h2>Maintaining Endpoint Trust During the Patch Window<\/h2>\n<p>Organizations must remediate CVE-2026-20349 in the affected Cisco ASA and FTD software. Endpoint management, <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/access-control-explained\/\">access control<\/a>, and endpoint detection tools do not replace Cisco&#8217;s fix.<\/p>\n<p>Remote-access incidents also highlight the value of separate security controls. Organizations should manage network availability, endpoint posture, application access, and endpoint investigation as distinct layers.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\"><strong>Hexnode UEM<\/strong><\/a> can help IT teams maintain visibility into managed endpoints and enforce required device configurations and compliance policies while infrastructure teams address the vulnerable VPN layer.<\/li>\n<li>Hexnode UEM integrates with Okta Device Trust to support device-based application access. Okta checks whether devices meet the required security conditions before granting access.<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/xdr\/\"><strong>Hexnode XDR<\/strong><\/a> can support endpoint-focused investigation when a VPN disruption coincides with suspicious endpoint activity. Teams can review endpoint events, query historical endpoint data, and investigate suspicious endpoint activity. These capabilities help teams investigate activity on managed endpoints. Hexnode XDR does not detect exploitation of the Cisco appliance itself.<\/li>\n<\/ul>\n<p>The boundary is important: Hexnode UEM, supported identity integrations, and Hexnode XDR don&#8217;t remediate CVE-2026-20349. Cisco&#8217;s fixed software is the remediation. Their relevance here is in maintaining endpoint compliance, supporting device compliance- or trust-based access decisions through supported identity integrations, and providing endpoint investigation capabilities around the infrastructure incident.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp 287w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1-96x100.webp?format=webp 96w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" title=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore how UEM and XDR work together to strengthen endpoint visibility, security context, investigation, and response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can CVE-2026-20349 be exploited without authentication?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. It can be triggered remotely without an authenticated VPN session or user interaction, as long as the affected service is reachable.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What happens when attackers exploit CVE-2026-20349?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Attackers can cause an affected Cisco ASA or FTD device to reload. The reload can disrupt remote-access services.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does CVE-2026-20349 allow remote code execution?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No remote code execution has been reported. The documented impact is denial of service through device reload.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>The Bottom Line<\/h3>\n<p>CVE-2026-20349 is primarily an availability vulnerability, but its position in remote-access infrastructure makes that availability impact operationally significant.<\/p>\n<p>It&#8217;s remotely exploitable without authentication. Cisco has confirmed exploitation in the wild. No workaround addresses the vulnerability.<\/p>\n<p>For defenders, the response path is straightforward:<\/p>\n<ul>\n<li>Identify exposed ASA and FTD deployments<\/li>\n<li>Verify affected remote-access configurations<\/li>\n<li>Apply Cisco&#8217;s fixed software<\/li>\n<li>Validate services after remediation<\/li>\n<li>Investigate unexplained reloads where warranted<\/li>\n<\/ul>\n<p>The broader lesson matters just as much. Edge infrastructure doesn&#8217;t need to suffer full system compromise to create a serious security incident.<\/p>\n<p>Vulnerable edge devices can disrupt access to critical resources for employees, administrators, and incident responders. That makes availability an important part of the organization&#8217;s security posture.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Security Beyond the VPN<\/h5><p>Manage endpoint posture and security controls from Hexnode while your infrastructure teams address network-edge vulnerabilities.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cisco ASA and FTD administrators have another actively exploited edge-device vulnerability to address. CVE-2026-20349 is&#8230;<\/p>\n","protected":false},"author":4,"featured_media":505,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20,21],"class_list":["post-502","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-and-vpn","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2026-20349: Cisco ASA\/FTD VPN Flaw Exploited in the Wild<\/title>\n<meta name=\"description\" content=\"CVE-2026-20349 is an actively exploited Cisco ASA\/FTD VPN DoS flaw. See affected services, fixes and CISA\u2019s Aug. 14 deadline.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-20349: Cisco ASA\/FTD VPN Flaw Exploited in the Wild\" \/>\n<meta property=\"og:description\" content=\"CVE-2026-20349 is an actively exploited Cisco ASA\/FTD VPN DoS flaw. See affected services, fixes and CISA\u2019s Aug. 14 deadline.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-17T07:29:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:11:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"CVE-2026-20349: Cisco ASA and FTD VPN Flaw Exploited in the Wild\",\"datePublished\":\"2026-08-17T07:29:28+00:00\",\"dateModified\":\"2026-08-18T09:11:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/\"},\"wordCount\":1752,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp\",\"articleSection\":[\"Network and VPN\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/\",\"name\":\"CVE-2026-20349: Cisco ASA\\\/FTD VPN Flaw Exploited in the Wild\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp\",\"datePublished\":\"2026-08-17T07:29:28+00:00\",\"dateModified\":\"2026-08-18T09:11:03+00:00\",\"description\":\"CVE-2026-20349 is an actively exploited Cisco ASA\\\/FTD VPN DoS flaw. See affected services, fixes and CISA\u2019s Aug. 14 deadline.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"CVE-2026-20349 Cisco ASA and FTD VPN Flaw Exploited in the Wild\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-20349: Cisco ASA and FTD VPN Flaw Exploited in the Wild\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2026-20349: Cisco ASA\/FTD VPN Flaw Exploited in the Wild","description":"CVE-2026-20349 is an actively exploited Cisco ASA\/FTD VPN DoS flaw. See affected services, fixes and CISA\u2019s Aug. 14 deadline.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-20349: Cisco ASA\/FTD VPN Flaw Exploited in the Wild","og_description":"CVE-2026-20349 is an actively exploited Cisco ASA\/FTD VPN DoS flaw. See affected services, fixes and CISA\u2019s Aug. 14 deadline.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-17T07:29:28+00:00","article_modified_time":"2026-08-18T09:11:03+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"CVE-2026-20349: Cisco ASA and FTD VPN Flaw Exploited in the Wild","datePublished":"2026-08-17T07:29:28+00:00","dateModified":"2026-08-18T09:11:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/"},"wordCount":1752,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp","articleSection":["Network and VPN","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/","name":"CVE-2026-20349: Cisco ASA\/FTD VPN Flaw Exploited in the Wild","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp","datePublished":"2026-08-17T07:29:28+00:00","dateModified":"2026-08-18T09:11:03+00:00","description":"CVE-2026-20349 is an actively exploited Cisco ASA\/FTD VPN DoS flaw. See affected services, fixes and CISA\u2019s Aug. 14 deadline.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/CVE-2026-20349-Cisco-ASA-and-FTD-VPN-Flaw-Exploited-in-the-Wild.jpg?format=webp","width":1340,"height":754,"caption":"CVE-2026-20349 Cisco ASA and FTD VPN Flaw Exploited in the Wild"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-20349-cisco-asa-ftd-vpn-flaw\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-20349: Cisco ASA and FTD VPN Flaw Exploited in the Wild"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=502"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/502\/revisions"}],"predecessor-version":[{"id":507,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/502\/revisions\/507"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/505"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}