Number: AL26-018
Date: August 13, 2026
Active Exploitation of High-Severity Vulnerability CVE-2026-20349 in Cisco ASA and FTD Software
The Canadian Centre for Cyber Security (Cyber Centre) has issued an alert regarding the active exploitation of a critical vulnerability affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. This vulnerability, tracked as CVE-2026-20349, was disclosed by Cisco on August 11, 2026, and has been confirmed to be exploited in the wild.
CVE-2026-20349 is categorized as an Improper Clearing of Heap Memory Before Release vulnerability (CWE-244). It arises from insufficient error checking when processing HTTP requests, potentially allowing unauthenticated remote attackers to send specially crafted HTTP requests to an affected SSL VPN service. Successful exploitation could lead to unexpected firewall reloads, resulting in a denial-of-service (DoS) condition.
Impacted Systems
Organizations utilizing Cisco Secure Firewall ASA and FTD SSL VPN services that are accessible from the internet are particularly at risk, especially if they have the following features enabled:
- IKEv2 Remote Access VPN with client services
- SSL VPN (WebVPN)
- Zero Trust Network Access (ZTNA) (FTD only)
It is important to note that Cisco Secure Firewall Management Center (FMC) Software is not affected by this vulnerability.
Recommended Actions
The Cyber Centre advises organizations to take the following steps to mitigate the risk:
- Identify any internet-accessible Cisco Secure Firewall ASA and FTD systems that provide Remote Access SSL VPN services.
- Check if WebVPN, IKEv2 Remote Access VPN (with client services), or ZTNA features are enabled.
- Review firewall and VPN logs for signs of unexpected reloads, service interruptions, or suspicious HTTP requests targeting SSL VPN services.
- Prioritize the remediation of internet-facing systems.
Organizations should upgrade affected Cisco ASA instances to the following fixed versions:
| Affected product | Affected versions | Fixed versions |
|---|---|---|
| Cisco ASA | 9.16.x | 89.16.4.50 |
| Cisco ASA | 9.18.x | 89.18.4.50 |
| Cisco ASA | 9.20.x | 9.20.4.235 |
| Cisco ASA | 9.22.x | 9.22.3.191 |
| Cisco ASA | 9.23.x | 9.23.1.211 |
| Cisco ASA | 9.24.x | 9.24.1.221 |
| Cisco Secure Firewall FTD Software | 7.0.x | 7.0.9.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.2.x | 7.2.11.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.4.x | 7.4.7.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.6.x | 7.6.4.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.7.x | 7.7.11.1 Hotfix |
| Cisco Secure Firewall FTD Software | 10.0.x | 10.0.0.1 Hotfix |
Additionally, organizations should:
- Review the Cisco advisory and assess exposure using the Cisco Software Checker.
- Incorporate perimeter devices and VPN gateways into vulnerability and patch management programs.
- Monitor network infrastructure for service disruptions and signs of attempted exploitation.
- Consolidate and defend internet gateways.
- Patch operating systems, applications, and network infrastructure promptly.
- Harden exposed services and limit unnecessary internet-facing management interfaces.
- Follow Cisco’s remediation guidance and CISA KEV recommendations.
For further details, refer to the full advisory from the Canadian Centre for Cyber Security here.
Readers can also explore current and upcoming editions through the Cyber Warriors Middle East Resources section.


