Attackers are already exploiting a high-severity flaw that can force vulnerable Cisco ASA and FTD firewalls to restart remotely.
CVE-2026-20349 affects Cisco Secure Firewall software and can trigger a denial-of-service condition without requiring authentication. Cisco has released fixed software, so organizations still running vulnerable deployments face immediate exposure.
Security teams responsible for these appliances need to confirm whether their software and remote access configuration are affected. A forced reload is not equivalent to device compromise, but it can interrupt access at a critical point in the network.
Remote access VPN service exposes the crash path
According to Cisco, the vulnerability stems from insufficient error checking when affected ASA or FTD software processes HTTP requests sent to the Remote Access SSL VPN service. A crafted request can trigger an unexpected reload and cause a denial of service.
Valid VPN credentials are not required, and Cisco rates the flaw 8.6 out of 10. The reported impact is denial of service, with exploitation forcing an affected device to reload.
Exposure depends on the software release and whether the vulnerable service is enabled. Administrators should verify their configurations against the vendor advisory instead of assuming every ASA or FTD appliance faces the same risk. Existing VPN security practices can also help teams review how internet-facing remote access is controlled.
Firewall reloads can become operational incidents
If you manage Cisco ASA or FTD appliances at the network edge, I would treat an unexplained reload as a potential security event until its cause is established. A device returning to service after a restart does not explain why it failed or whether someone deliberately triggered it.
First, identify appliances exposing the affected remote access service and determine which ones support critical connectivity. Vulnerability scanning tools can help uncover systems that have fallen outside routine tracking, but configuration checks still need to be matched against the vendor’s advisory.
Redundancy deserves a separate review. Failover may reduce downtime if one appliance reloads, but security teams should confirm whether their firewall security practices account for repeated failures and whether recovery controls perform as expected.
Also review logs and crash records around unexplained restarts, particularly on internet-facing systems. ASA and FTD products have faced previous active exploitation, giving administrators another reason to investigate abnormal behavior instead of treating every restart as a routine fault.
Fixed software is available, and patching should come next
Cisco has released software updates addressing CVE-2026-20349. Administrators can use the fixed-release information and Software Checker referenced in the advisory to determine the appropriate update for each affected deployment.
No workaround removes the vulnerability, making an upgrade to a fixed release the primary remediation. Organizations using formal patch and vulnerability management programs should prioritize exposed devices because exploitation has already been observed.
With fixes already available, vulnerable internet-facing deployments remain the part organizations can act on now. Security teams should move affected appliances onto a fixed release as soon as operationally feasible.
Microsoft warns DeadLock can remain operational after server seizures, complicating efforts to disrupt the ransomware group.





