None
EN
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
['The Hacker News', 'Ravie Lakshmanan', 'Aug']
The Hacker News
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild.
The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device," Cisco said in a Tuesday advisory.
"A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition."
The network equipment maker said the issue was found during internal security testing.