Cisco Firewall Alert: Hackers Exploit ASA, FTD Flaw to Force Remote Restarts

Cisco patches an actively exploited ASA and FTD flaw that can remotely crash vulnerable firewalls, prompting security teams to prioritize updates now.

執筆者
Liz Ticong
Liz Ticong
Aug 13, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Attackers are already exploiting a high-severity flaw that can force vulnerable Cisco ASA and FTD firewalls to restart remotely.

CVE-2026-20349 affects Cisco Secure Firewall software and can trigger a denial-of-service condition without requiring authentication. Cisco has released fixed software, so organizations still running vulnerable deployments face immediate exposure.

Security teams responsible for these appliances need to confirm whether their software and remote access configuration are affected. A forced reload is not equivalent to device compromise, but it can interrupt access at a critical point in the network.

Remote access VPN service exposes the crash path

According to Cisco, the vulnerability stems from insufficient error checking when affected ASA or FTD software processes HTTP requests sent to the Remote Access SSL VPN service. A crafted request can trigger an unexpected reload and cause a denial of service.

Valid VPN credentials are not required, and Cisco rates the flaw 8.6 out of 10. The reported impact is denial of service, with exploitation forcing an affected device to reload.

Exposure depends on the software release and whether the vulnerable service is enabled. Administrators should verify their configurations against the vendor advisory instead of assuming every ASA or FTD appliance faces the same risk. Existing VPN security practices can also help teams review how internet-facing remote access is controlled.

Firewall reloads can become operational incidents

If you manage Cisco ASA or FTD appliances at the network edge, I would treat an unexplained reload as a potential security event until its cause is established. A device returning to service after a restart does not explain why it failed or whether someone deliberately triggered it.

First, identify appliances exposing the affected remote access service and determine which ones support critical connectivity. Vulnerability scanning tools can help uncover systems that have fallen outside routine tracking, but configuration checks still need to be matched against the vendor’s advisory.

Advertisement

Redundancy deserves a separate review. Failover may reduce downtime if one appliance reloads, but security teams should confirm whether their firewall security practices account for repeated failures and whether recovery controls perform as expected.

Also review logs and crash records around unexplained restarts, particularly on internet-facing systems. ASA and FTD products have faced previous active exploitation, giving administrators another reason to investigate abnormal behavior instead of treating every restart as a routine fault.

Fixed software is available, and patching should come next

Cisco has released software updates addressing CVE-2026-20349. Administrators can use the fixed-release information and Software Checker referenced in the advisory to determine the appropriate update for each affected deployment.

No workaround removes the vulnerability, making an upgrade to a fixed release the primary remediation. Organizations using formal patch and vulnerability management programs should prioritize exposed devices because exploitation has already been observed.

With fixes already available, vulnerable internet-facing deployments remain the part organizations can act on now. Security teams should move affected appliances onto a fixed release as soon as operationally feasible.

Microsoft warns DeadLock can remain operational after server seizures, complicating efforts to disrupt the ransomware group.

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。