Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    August 12, 2026

    Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

    August 11, 2026

    Company Offering ‘100% Human-Written, Never AI’ Medical Research Is Entirely AI

    August 11, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Cisco warns of ASA and FTD VPN flaw exploited to crash devices
    News

    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    adminBy adminAugust 12, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cisco

    Cisco is warning that a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense (FTD) software is being actively exploited in attacks to remotely crash affected devices.

    The flaw, tracked as CVE-2026-20349, has a severity score of 8.6 and impacts devices running Cisco Secure Firewall Adaptive Security Appliance (ASA) or Secure Firewall Threat Defense (FTD) software with certain remote access services enabled.

    In a security advisory published today, Cisco said the vulnerability is caused by insufficient error checking while processing HTTP requests.

    image

    “An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device,” Cisco explains in the advisory.

    “A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.”

    The vulnerability can be exploited remotely without authentication or user interaction when SSL listen sockets are enabled.

    Vulnerable configurations include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices. Cisco says Secure Firewall Management Center (FMC) software is not affected.

    Cisco has released hot fixes for affected ASA 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 releases, as well as FTD releases 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0.

    There are no workarounds for the vulnerability, and Cisco strongly recommends that customers upgrade to a fixed software release to fully remediate the issue.

    Cisco’s PSIRT says it became aware of active exploitation of CVE-2026-20349 in August 2026, but the company has not shared additional information about the attacks, including who is exploiting the vulnerability or what organizations are being targeted.

    The vulnerability was also discovered during Cisco’s internal security testing and independently reported to the company by security researcher Valerio Brussani.

    Cisco’s advisory does not provide indicators of compromise associated with the ongoing exploitation.

    The company also disclosed this month that Secure Endpoint Connector for Windows, Mac, and Linux is vulnerable to ClamAV vulnerabilities with public exploits.

    However, the patches are not available yet and will be released later this month.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
    admin
    • Website

    Related Posts

    News

    Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

    August 11, 2026
    News

    Company Offering ‘100% Human-Written, Never AI’ Medical Research Is Entirely AI

    August 11, 2026
    News

    CIS Benchmarks August 2026 Update

    August 11, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    August 12, 2026

    Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

    August 11, 2026

    Company Offering ‘100% Human-Written, Never AI’ Medical Research Is Entirely AI

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.