INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

| 2026-08-12 06:15 HIGH HIGH
Executive Summary AI-generated
The recent incident data reveals a critical vulnerability in Cisco ASA and FTD software, which has been exploited in the wild. The flaw, tracked as CVE-2026-20349 with a CVSS score of 8.6, allows an unauthenticated remote attacker to trigger a denial-of-service condition by exploiting insufficient error checking when processing HTTP requests. This vulnerability affects devices running vulnerable versions of Secure Firewall ASA Software or Cisco Secure FTD Software and has been fixed in various software versions ranging from 9.161 to 10.0. The affected software includes IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access, and the aforementioned versions of ASA and FTD.
Technical Mitigations AI-generated
* Implement secure configuration practices, such as disabling IKEv2 Remote Access VPN (with client services) and crypto ikev2 enable client-services port SSL-VPN on ASA devices. * Regularly update and patch FTD software to ensure you have the latest security fixes. * Configure FTD devices with a strong firewall policy, including enabling SSL-VPN and setting up secure access controls. * Monitor network traffic for suspicious activity and implement intrusion detection systems (IDS) or firewalls to block unauthorized access.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20349CVE-2026-20349
Target & Sectors
Global Scope defensedefense
Incident Timeline
‎2026/08/11
Threat actors exploited a vulnerability in Cisco ASA firewalls by using it to target FTD devices.
‎Aug 12, 2026
Cisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tar.
organisation DoS
infrastructure 9.181
infrastructure 89.18.4
organisation ASA 9.181 - Fixed
infrastructure 9.20
infrastructure 9.20.4
infrastructure 9.22
infrastructure 9.22.3
infrastructure 9.23
infrastructure 9.23.1
infrastructure 9.24
infrastructure 9.24.1
infrastructure 7.0
infrastructure 7.0.9
infrastructure 7.2
infrastructure 7.2.11
infrastructure 7.4
infrastructure 7.4.7
infrastructure 7.6
infrastructure 7.6.4
infrastructure 7.7
infrastructure 7.7.11
infrastructure 10.0
infrastructure 10.0.0
organisation Cisco_FTD_SSP_Hotfix_HK-7.4.7.1-1.sh.REL.tar
organisation Cisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tar
organisation FTD 7.0 - Fixed
organisation FTD 7.2 - Fixed
organisation FTD 7.7 - Fixed
organisation Cisco
organisation the Remote Access SSL VPN
‎August 2026
Threat actors exploited CVE-2026-20349 in the wild, targeting organizations.
vulnerability CVE-2026-20349
‎2026/08/12
Threat actors exploited a vulnerability in Cisco ASA and FTD software to target devices with certain remote access services enabled.
organisation Cisco ASA
organisation FTD Flaw Exploited
organisation Network Security / Vulnerability
organisation Secure Firewall Adaptive Security Appliance
organisation Secure Firewall Threat Defense
organisation Secure Firewall ASA
organisation Threat Defense
infrastructure 8.6
organisation Cisco Secure Firewall Adaptive Security Appliance
infrastructure 9.161
infrastructure 89.16.4
organisation Cisco Secure FTD
organisation IKEv2 Remote Access VPN
organisation Zero Trust Network Access2 - zero
organisation ASA
organisation FTD
organisation FTD VPN
infrastructure 9.20
infrastructure 9.22
infrastructure 9.23
infrastructure 9.24
infrastructure 7.0
infrastructure 7.2
infrastructure 7.4
infrastructure 7.6
infrastructure 7.7
infrastructure 10.0
infrastructure 9.16
infrastructure 9.18
organisation Cisco
organisation Secure Firewall Management Center
organisation the Remote Access SSL VPN
infrastructure Windows
infrastructure Linux
organisation Secure Endpoint
organisation Windows, Mac
organisation ClamAV
organisation SSL
organisation IKEv2 Remote Access
organisation SSL VPN
organisation Zero Trust Network Access on FTD
organisation The Blue Report 2026
‎August 14, 2026
Threat actors exploited the Cisco ASA and FTD Flaw.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎9.161
Software Version
Metrics
infrastructure
‎89.16.4
Software Version
Metrics
infrastructure
‎9.181
Software Version
Metrics
infrastructure
‎89.18.4
Software Version
Metrics
infrastructure
‎9.20
Software Version
Metrics
infrastructure
‎9.20.4
Software Version
Metrics
infrastructure
‎9.22
Software Version
Metrics
infrastructure
‎9.22.3
Software Version
Metrics
infrastructure
‎9.23
Software Version
Metrics
infrastructure
‎9.23.1
Software Version
Metrics
infrastructure
‎9.24
Software Version
Metrics
infrastructure
‎9.24.1
Software Version
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎7.0.9
Software Version
Metrics
infrastructure
‎7.2
Software Version
Metrics
infrastructure
‎7.2.11
Software Version
Metrics
infrastructure
‎7.4
Software Version
Metrics
infrastructure
‎7.4.7
Software Version
Metrics
infrastructure
‎7.6
Software Version
Metrics
infrastructure
‎7.6.4
Software Version
Metrics
infrastructure
‎7.7
Software Version
Metrics
infrastructure
‎7.7.11
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎10.0.0
Software Version
Metrics
infrastructure
‎8.6
Software Version
Metrics
infrastructure
‎9.16
Software Version
Metrics
infrastructure
‎9.18
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources