bleeping-computer · Crawled Aug 11, 2026

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

Read original article ↗

AI Summary

Cisco has warned of active exploitation of a high-severity denial-of-service vulnerability, CVE-2026-20349, in its Secure Firewall ASA and Threat Defense (FTD) software. The flaw stems from insufficient error checking when processing HTTP requests, allowing an unauthenticated remote attacker to crash affected devices by sending a crafted HTTP request to the SSL VPN service. Exploitation leads to a reload of the device, causing a DoS condition, and no workarounds exist—only patching with fixed software releases mitigates the issue.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.