A flaw in Cisco ASA/FTD edge firewalls (CVE-2026-20349) — unauthenticated attackers can force a reload and cut traffic
Cisco Secure Firewall ASA and Threat Defense (FTD) contain a vulnerability that could let an unauthenticated remote attacker cause the device to reload unexpectedly, producing a denial-of-service condition. CISA added it to KEV on August 11, 2026 with a due date of August 14.
Key facts
- CVE IDCVE-2026-20349
- Affected (vendor / product)Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
- CWECWE-244
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-08-14 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Affected: Cisco Secure Firewall ASA and Threat Defense (FTD). CWE-244.
- An unauthenticated remote attacker could cause the device to reload unexpectedly, producing denial of service.
- Not theft or code execution, but if an edge defense device stops, the work behind it stops with it.
- Added to KEV 2026-08-11 with a due date of 2026-08-14 — three days.
- Edge devices must be reachable from the internet, so an attack requiring no authentication needs no prior intrusion.
- Nothing leaks, yet a reloaded edge device stops the traffic and everything behind it stops together.
1Not a theft-of-information vulnerability
Most KEV entries lead to code execution or data theft. This one leads to neither: it causes the device to reload unexpectedly, which stops traffic. It still gets the most urgent handling because of what the device is. If a firewall or VPN terminator goes down, the work behind it stops together. Nothing leaks, and the business still halts.
2Why edge devices are targeted
ASA and FTD sit at the boundary of an organization's network and are the first to receive traffic from outside. By nature that position has to be reachable from the internet, which makes it a target permanently in view. If an attack works without authentication, no prior intrusion and no stolen credentials are required. That structure is why edge-device vulnerabilities appear in KEV again and again.
3A three-day remediation deadline
KEV addition on 2026-08-11 and a due date of 2026-08-14 leave three days. CISA requires applying mitigations per vendor instructions and complying with BOD 26-04 (Prioritizing Security Updates Based on Risk) and the Forensics Triage Requirements. Updating an edge device involves an interruption in traffic and therefore planned work, and three days leaves little room to arrange it.
4Nothing leaks, and the business still stops
Most KEV entries lead to arbitrary code execution or theft of information. This one does neither. It causes an unexpected reload — that is, it stops the traffic.
It nonetheless receives the highest handling because the subject is a perimeter defence device. If a firewall or VPN terminator falls, everything behind it stops together. Updating edge devices involves an outage and needs planning, and three days from listing means very little room for that arrangement. Whether redundancy exists and how failover is performed, established in peacetime, decide whether the deadline can be met.
Why it matters
Updating edge devices interrupts traffic, so meeting the deadline comes down almost entirely to whether redundancy and failover procedures are in place. Even a vulnerability that affects only availability deserves a place in risk assessment under the criterion that the business stops when that device stops.
FAQ
Why is a denial-of-service flaw treated as top priority?
Why do edge-device vulnerabilities keep appearing?
What if three days is not enough?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).