Site icon VMVirtualMachine.com

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) – Help Net Security

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-08-13 07:30:00

A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed.

The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026.

Details about the attacks are currently under wraps. Cisco only shared that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability in August 2026.

About CVE-2026-20349

CVE-2026-20349 affects the Remote Access SSL VPN service for:

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software

Affected features are IKEv2 Remote Access VPN (with client services), SSL VPN, and Zero Trust Network Access (ZTNA). An appliance is vulnerable to attack if it runs an affected software version and if one of these features is enabled (i.e., the SSL listen…

Exit mobile version