Skip to content
CiscoCVE-2026-20349

Cisco Secure Firewall: denial of service

High8.6CVE-2026-20349 · Published Aug 11, 2026 · updated Sep 16, 2026

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Product
<= 9.16.1No fix yet
<= 9.16.1.28No fix yet
<= 9.16.2No fix yet
<= 9.16.2.3No fix yet
Cisco Secure Firewall Threat Defense (FTD) Software
Product
<= 7.0.0No fix yet
<= 7.0.0.1No fix yet
<= 7.0.1No fix yet
<= 7.0.1.1No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Secure Endpoint: denial of service
High7.5Aug 7
Cisco Secure Endpoint: denial of service
High7.5Aug 7
Cisco Secure Endpoint: denial of service
High7.5Aug 7
Cisco Secure Endpoint: denial of service
High7.5Aug 7
Cisco Secure Endpoint: denial of service
High7.5Aug 7
Cisco Secure Endpoint: denial of service
High7.5Aug 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.