Exploited Known exploited (KEV) CVE-2026-20349

A flaw in Cisco ASA/FTD edge firewalls (CVE-2026-20349) — unauthenticated attackers can force a reload and cut traffic

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Added to KEV Aug 11, 2026 Federal remediation due 2026-08-14

Cisco Secure Firewall ASA and Threat Defense (FTD) contain a vulnerability that could let an unauthenticated remote attacker cause the device to reload unexpectedly, producing a denial-of-service condition. CISA added it to KEV on August 11, 2026 with a due date of August 14.

Key facts

  • CVE IDCVE-2026-20349
  • Affected (vendor / product)Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
  • CWECWE-244
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-08-14 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Affected: Cisco Secure Firewall ASA and Threat Defense (FTD). CWE-244.
  • An unauthenticated remote attacker could cause the device to reload unexpectedly, producing denial of service.
  • Not theft or code execution, but if an edge defense device stops, the work behind it stops with it.
  • Added to KEV 2026-08-11 with a due date of 2026-08-14 — three days.
  • Edge devices must be reachable from the internet, so an attack requiring no authentication needs no prior intrusion.
  • Nothing leaks, yet a reloaded edge device stops the traffic and everything behind it stops together.

1Not a theft-of-information vulnerability

Most KEV entries lead to code execution or data theft. This one leads to neither: it causes the device to reload unexpectedly, which stops traffic. It still gets the most urgent handling because of what the device is. If a firewall or VPN terminator goes down, the work behind it stops together. Nothing leaks, and the business still halts.

2Why edge devices are targeted

ASA and FTD sit at the boundary of an organization's network and are the first to receive traffic from outside. By nature that position has to be reachable from the internet, which makes it a target permanently in view. If an attack works without authentication, no prior intrusion and no stolen credentials are required. That structure is why edge-device vulnerabilities appear in KEV again and again.

3A three-day remediation deadline

KEV addition on 2026-08-11 and a due date of 2026-08-14 leave three days. CISA requires applying mitigations per vendor instructions and complying with BOD 26-04 (Prioritizing Security Updates Based on Risk) and the Forensics Triage Requirements. Updating an edge device involves an interruption in traffic and therefore planned work, and three days leaves little room to arrange it.

4Nothing leaks, and the business still stops

Most KEV entries lead to arbitrary code execution or theft of information. This one does neither. It causes an unexpected reload — that is, it stops the traffic.

The kind where information is stolenThe kind where traffic stops (this record)
Confidentiality and integrity are lostAvailability is lost
The damage is hard to noticeThe damage is immediately obvious
Recovery is investigation and containmentRecovery is a reload and a failover
If nothing leaked the harm is smallNothing leaks and the business still stops

It nonetheless receives the highest handling because the subject is a perimeter defence device. If a firewall or VPN terminator falls, everything behind it stops together. Updating edge devices involves an outage and needs planning, and three days from listing means very little room for that arrangement. Whether redundancy exists and how failover is performed, established in peacetime, decide whether the deadline can be met.

Why it matters

Updating edge devices interrupts traffic, so meeting the deadline comes down almost entirely to whether redundancy and failover procedures are in place. Even a vulnerability that affects only availability deserves a place in risk assessment under the criterion that the business stops when that device stops.

FAQ

Why is a denial-of-service flaw treated as top priority?
Because of what the device is. If a firewall or VPN terminator stops, the work behind it stops together, even though nothing leaks.
Why do edge-device vulnerabilities keep appearing?
By nature they must be reachable from the internet, which makes them a target permanently in view.
What if three days is not enough?
Check whether the mitigations in the vendor advisory apply and whether a redundant deployment allows failover. Make the applicability judgment in your own environment.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Cisco#Firewall#Denial of service
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.