Your Cisco Firewall Can Be Knocked Offline From the Internet. No Credentials Required. Federal Agencies Had Until Last Thursday to Fix It.
Nobody calls the IT person when the VPN goes down at 8 AM. They try it three times, reboot the laptop, blame the home internet, and eventually give up. By the time IT hears about it, half the workday is gone. That scenario is a real risk right now for any business running a Cisco ASA or Cisco Secure Firewall.
There’s a flaw under active exploitation that lets an attacker crash those devices from the internet with no login required. No username. No password. Not even a wrong guess at your VPN credentials. Just a crafted HTTP request, sent from anywhere, and the device restarts.[1]
What This Vulnerability Actually Does
The vulnerability is CVE-2026-20349, scored 8.6 out of 10 on the Common Vulnerability Scoring System.[2] It lives in the remote-access VPN service on Cisco ASA and Firepower Threat Defense (FTD) hardware. When an attacker sends a specially crafted HTTP request to that service, the affected device crashes and reloads.
For a typical small business, the Cisco ASA handles two jobs at once: it’s the firewall between your network and the internet, and it’s the VPN endpoint your remote employees connect through to reach internal systems. When that device crashes, both functions stop. Remote workers lose access. And if an attacker keeps sending those requests, the device never fully recovers. It’s the network equivalent of someone leaning on the front door buzzer until you can’t hear anything else.
Cisco confirmed their Product Security Incident Response Team became aware of active exploitation earlier this month.[1] They haven’t shared details on who is behind the attacks or what organizations have been targeted, but the confirmation of active attacks is what matters here.
CISA Added It to the KEV Catalog. The Federal Deadline Already Passed.
After Cisco confirmed active exploitation, CISA added CVE-2026-20349 to their Known Exploited Vulnerabilities catalog and set a remediation deadline of August 14, 2026 for all U.S. federal civilian agencies.[3] That was last Thursday.
The KEV catalog is worth understanding if you’re not familiar with it. CISA maintains it as a running list of vulnerabilities confirmed to be actively exploited in the wild. The deadlines it sets are technically a compliance requirement for federal agencies, but the list is public and it’s one of the clearest signals available to everyone else: if something makes the KEV list, it’s not theoretical. Someone is already using it against real organizations.
The flaw affects any device running Cisco ASA or FTD software with SSL Remote Access VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled. Affected ASA versions include 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24. Affected FTD versions include 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.[1]
There is no workaround. Disabling remote-access VPN would prevent exploitation, but that’s the same as locking your front door by taking the door off. The only actual fix is the hot fix Cisco released for each affected version.
Two Questions to Ask Your IT Provider
You don’t need to know the technical details. You need two answers from whoever manages your network equipment:
First, do we use Cisco ASA or Cisco Firepower (FTD) for our firewall or remote access VPN? Second, has CVE-2026-20349 been patched, and when?
An IT provider actively managing Cisco security appliances should have been tracking this the day it hit CISA’s catalog. If they haven’t heard of it, or they can’t tell you whether they’ve patched it, that’s useful information about how proactively they’re managing your security posture.
One side note worth mentioning: Microsoft’s August 2026 Patch Tuesday also landed last week with 421 vulnerabilities fixed, including a Windows kernel zero-day (CVE-2026-68820) that North Korean hackers had been exploiting for weeks to install a hard-to-detect rootkit on target machines.[4] That campaign was aimed at defense contractors, not small businesses. But the Windows patch applies to all of us, and it’s a reminder that last week had a lot of critical security news hit at once. If your IT team hasn’t been in touch about any of it, it’s a good week to ask.
Not sure what’s running your remote access, or when the last security update was applied? Reach out here or call us at (412) 307-8313. We help small businesses in the Pittsburgh area stay on top of exactly this kind of thing.
- Cisco, “Cisco Secure Firewall ASA and FTD Software Remote Access SSL VPN Denial of Service Vulnerability (cisco-sa-asaftd-vpn-dos-dzv4mQFF),” cisco.com
- CyCognito, “Emerging Threat: CVE-2026-20349 Cisco ASA and FTD Denial of Service via Remote Access SSL VPN,” cycognito.com
- CISA, “Known Exploited Vulnerabilities Catalog,” cisa.gov
- SecurityWeek, “August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day,” securityweek.com