peter bassill · operator
$ cve CVE-2026-20349 JSON

CVE-2026-20349 KEV

8.6
HIGH · CVSS 3.1 · EPSS 1% (pctl 62)

Patch first

On CISA KEV — known exploited in the wild, due 2026-08-14.

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Scoring

CVSS8.6 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS1.01% — more likely to be exploited than 62% of all CVEs
WeaknessCWE-244
On CISA KEVyes — remediate by 2026-08-14
Public exploitnone known
Published2026-08-11
Last modified2026-09-16

CISA KEV

NameCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Added2026-08-11
Due2026-08-14
Vendor / productCisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Ransomware usenone reported

Affected (2)

VendorProduct
ciscoadaptive security appliance software
ciscosecure firewall threat defense

References

→ the Explorer  ·  watch your stack  ·  NVD