Cisco has confirmed active exploitation of CVE-2026-20349, a high-severity denial-of-service flaw in Secure Firewall ASA and FTD VPN services, with hotfixes already issued but no workaround available. For UK organisations running Cisco secure edge infrastructure to support hybrid and remote access, this is an immediate patch-now situation.
View the data behind this chart
| Global exposure | UK exposure | |
|---|---|---|
| Exposed ASA/FTD devices | devices48800 | devices2800 |
What is CVE-2026-20349 and why is it urgent?
Cisco's security advisory, published on 11 August 2026, discloses a vulnerability rated 8.6 out of 10 affecting Secure Firewall ASA and Secure Firewall Threat Defense (FTD) software wherever certain remote access VPN services are enabled. The root cause is insufficient error checking while the device processes HTTP requests sent to the Remote Access SSL VPN service.
Cisco's PSIRT says it became aware of active exploitation in August 2026, though the company has not disclosed who is behind the attacks, which organisations are being targeted, or any indicators of compromise. The flaw was found independently through Cisco's internal testing and by security researcher Valerio Brussani, but that dual discovery hasn't slowed real-world abuse.
How the exploit crashes ASA and FTD devices
An attacker sends a specially crafted HTTP request to the Remote Access SSL VPN service, and Cisco confirms this can be done remotely, without authentication and without any user interaction, provided SSL listen sockets are enabled on the device. A successful attempt forces the appliance to reload, producing a straightforward but disruptive denial-of-service condition.
Vulnerable configurations include IKEv2 Remote Access VPN with client services, standard SSL VPN, and Zero Trust Network Access on FTD devices. If you're weighing how ZTNA deployments fit into this risk picture, it's worth taking time to understand Zero Trust Network Access configurations and where they intersect with legacy VPN services on the same appliance. Cisco Secure Firewall Management Center (FMC) software is explicitly not affected, so the exposure sits squarely on internet-facing ASA and FTD boxes handling remote access.
Why UK firms running Cisco secure edge infrastructure should care
Hybrid and remote working models still lean heavily on VPN concentrators for staff and third-party access, which means any ASA or FTD device with SSL VPN or IKEv2 client services switched on is a candidate for this attack. Even where the impact is "only" a reload rather than data theft, an unplanned outage on a VPN gateway can lock out an entire remote workforce during business hours.
This isn't an isolated incident for the platform. The UK's National Cyber Security Centre has previously warned that Cisco firewall-platform vulnerabilities are actively exploited, and a separate recent report found roughly 48,800 internet-exposed Cisco ASA/FTD appliances vulnerable to known exploited flaws worldwide, with around 2,800 of those sitting in the UK. In that earlier campaign, the NCSC noted attackers deployed a shellcode loader and a GRUB bootkit — evidence that Cisco VPN-edge compromise has previously escalated well beyond simple disruption. Teams managing this estate should explore network security solutions that reduce reliance on a single exposed VPN chokepoint.

Patch availability: hotfixes for ASA and FTD releases
Cisco has already released hotfixes covering affected ASA releases 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, and FTD releases 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. Crucially, Cisco states there is no workaround for CVE-2026-20349 — upgrading to a fixed software release is the only way to fully remediate the issue.
This lack of a mitigating configuration change puts pressure on change-control windows. Organisations that have deferred patching cycles for stability reasons should still learn more about vulnerability management practices that allow emergency hotfix deployment outside standard release schedules, particularly for internet-facing VPN gateways.
A pattern of Cisco VPN-edge exploitation
CVE-2026-20349 lands in a well-established pattern. Cisco has previously disclosed ASA/FTD web-services and VPN flaws — including CVE-2024-20353 and CVE-2024-20359 — that the NCSC flagged as actively exploited before broad patching completed. This month Cisco also disclosed that its Secure Endpoint Connector is vulnerable to ClamAV flaws with public exploit code, though patches for those are not yet available and are due later in August 2026.
For buyers weighing whether to keep extending life on ageing ASA hardware or accelerate a platform refresh, it's a reasonable moment to compare the best firewalls for UK businesses against total cost of continued patch-and-pray operations on legacy edge appliances.
What UK infrastructure buyers should do now
Immediate priorities: inventory every ASA and FTD device with SSL VPN, IKEv2 client services or ZTNA enabled, confirm exposure to internet-facing SSL listen sockets, and apply the relevant hotfix without waiting for a routine maintenance window, since no workaround exists. Watch for unexplained device reloads as a possible early sign of exploitation attempts.
Longer term, this incident adds to the case for reducing dependency on always-on remote access VPN concentrators as a single point of failure. Firms reassessing their remote access architecture may want to migrate from VPN to ZTNA to shrink the attack surface these repeated ASA/FTD advisories keep exposing.
- 01BleepingComputer — Cisco warns of ASA and FTD VPN flaw exploited to crash devices · 11 August 2026
- 02Cisco Security Advisory — ASA/FTD Remote Access VPN DoS · 11 August 2026
- 03NCSC — Exploitation of vulnerabilities affecting Cisco firewall platforms · 11 August 2026
- 04BleepingComputer — Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws · 11 August 2026
- 05Dark Reading — Cisco ASA, FTD Software Face Active VPN Exploitation · 11 August 2026
