The Canadian Centre for Cyber Security published alert AL26-018 on August 13 for CVE-2026-20349, a high-severity flaw (CVSS 8.6) in Cisco Secure Firewall ASA and Threat Defense (FTD) software. Cisco has confirmed it is being exploited in the wild.
The bug sits in the Remote Access SSL VPN service. A remote attacker can send a crafted HTTP request, with no login and no user interaction, and force the device to reload. Repeat the request and the firewall stays down. Because the same box is usually both the perimeter enforcement point and the remote-access path for staff, one exploit takes out protection and remote work at the same time.
Affected versions run from ASA 9.16.x through 9.24.x and FTD 7.0.x through 10.0.x. The root cause is improper clearing of heap memory before release (CWE-244).
What to do, in order:
- Find every internet-facing ASA or FTD that runs Remote Access SSL VPN. Those are the exposed ones.
- Upgrade to a fixed release listed in Cisco’s advisory (cisco-sa-asaftd-vpn-dos-dzv4mQFF). There is no configuration change that fully removes the risk.
- Review firewall and VPN logs for unexpected reloads, dropped service, or odd HTTP requests hitting the SSL VPN, which can point to attempted or successful exploitation.
For Canadian security and network trades this one reaches past the IT closet. These firewalls often carry the same links as camera, access control, and alarm traffic, so a crash can pull a security system down with it. US federal agencies were given until August 14 to remediate under CISA’s Known Exploited Vulnerabilities catalogue, which is a fair marker for how urgent this is.
If you manage Cisco edge gear for clients, treat this as a same-week job.