Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
8.6
CVE-2026-20349
cis · adaptive_security_appliance_software

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Affected Products

VendorProductVersions
cisadaptive_security_appliance_software9.16.1, 9.16.1.28, 9.16.2, 9.16.2.3, 9.16.2.7, 9.16.2.11, 9.16.2.13, 9.16.2.14, 9.16.3.3, 9.16.3, 9.16.3.14, 9.18.1, 9.16.3.15, 9.18.1.3, 9.18.2, 9.16.3.19, 9.16.3.23, 9.18.2.5, 9.16.4, 9.18.2.7, 9.19.1, 9.16.4.9, 9.18.2.8, 9.16.4.14, 9.18.3, 9.19.1.5, 9.19.1.9, 9.18.3.39, 9.16.4.19, 9.19.1.12, 9.18.3.46, 9.16.4.27, 9.19.1.18, 9.18.3.53, 9.18.3.55, 9.16.4.38, 9.16.4.39, 9.18.3.56, 9.20.1, 9.16.4.42, 9.19.1.22, 9.18.4, 9.20.1.5, 9.18.4.5, 9.19.1.24, 9.16.4.48, 9.18.4.8, 9.20.2, 9.19.1.27, 9.16.4.55, 9.18.4.22, 9.20.2.10, 9.16.4.57, 9.19.1.28, 9.18.4.24, 9.20.2.21, 9.16.4.61, 9.19.1.31, 9.18.4.29, 9.20.2.22, 9.16.4.62, 9.18.4.34, 9.20.3, 9.16.4.67, 9.16.4.70, 9.18.4.40, 9.23.1, 9.22.1.1, 9.16.4.71, 9.20.3.4, 9.18.4.47, 9.20.3.7, 9.19.1.37, 9.16.4.76, 9.20.3.9, 9.19.1.38, 9.18.4.50, 9.22.1.3, 9.20.3.10, 9.22.1.2, 9.18.4.52, 9.20.3.13, 9.22.1.6, 9.18.4.53, 9.16.4.82, 9.22.2, 9.20.3.16, 9.19.1.42, 9.18.4.57, 9.16.4.84, 9.23.1.3, 9.20.3.20, 9.22.2.4, 9.23.1.7, 9.20.4, 9.22.2.9, 9.23.1.13, 9.20.4.7, 9.22.2.13, 9.18.4.66, 9.20.4.10, 9.23.1.19, 9.16.4.85, 9.22.2.14, 9.18.4.67, 9.24.1, 9.18.4.68, 9.23.1.22, 9.20.4.14, 9.22.2.20, 9.18.4.71, 9.20.4.19, 9.23.1.26, 9.16.4.89, 9.22.2.32, 9.18.4.76, 9.22.3, 9.24.1.5, 9.20.4.22, 9.24.1.9, 9.20.4.28, 9.22.3.5, 9.16.4.92, 9.18.4.135, 9.23.1.195, 9.20.4.30, 9.24.1.155, 9.23.1.32, 9.24.1.11, 9.20.4.34, 9.18.4.82, 9.18.4.90, 9.20.4.46, 7.0.0, 7.0.0.1, 7.0.1, 7.0.1.1, 7.0.2, 7.2.0, 7.0.2.1, 7.0.3, 7.2.0.1, 7.0.4, 7.2.1, 7.0.5, 7.3.0, 7.2.2, 7.2.3, 7.3.1, 7.2.4, 7.0.6, 7.2.5, 7.2.4.1, 7.3.1.1, 7.4.0, 7.0.6.1, 7.2.5.1, 7.4.1, 7.2.6, 7.0.6.2, 7.4.1.1, 7.2.7, 7.2.5.2, 7.3.1.2, 7.2.8, 7.6.0, 7.4.2, 7.2.8.1, 7.0.6.3, 7.4.2.1, 7.2.9, 7.0.7, 7.7.0, 7.4.2.2, 7.2.10, 7.6.1, 7.4.2.3, 7.0.8, 7.6.2, 7.7.10, 7.7.11, 7.0.8.1, 7.6.2.1, 7.7.10.1, 7.4.2.4, 7.2.10.2, 7.4.3, 7.6.4, 10.0.0, 7.4.4, 7.0.9, 7.2.11, 7.4.7, 7.4.8, 7.2.12, 7.7.13, 10.0.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisasa (adaptive security appliance)cert_advisory90%
ciscisco secure firewall threat defensecert_advisory90%
cissecure_firewall_threat_defensecve_cpe95%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF

Related News (12 articles)

Tier D
The Hacker News2d ago
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
→ No new info (linked only)
Tier B
CERT-FR7d ago
Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)
→ No new info (linked only)
Tier D
Help Net Security7d ago
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
→ No new info (linked only)
Tier B
CCCS Canada10d ago
AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349
→ No new info (linked only)
Tier D
Help Net Security10d ago
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
→ No new info (linked only)
Tier B
CCCS Canada11d ago
Cisco security advisory (AV26-807)
→ No new info (linked only)
Tier D
Heise Security11d ago
Cisco warnt vor Attacken auf Secure Firewall Adaptive Security Appliance
→ No new info (linked only)
Tier B
BSI Advisories11d ago
[NEU] [hoch] Cisco ASA (Adaptive Security Appliance) und Secure Firewall Threat Defense: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier D
The Hacker News12d ago
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
→ No new info (linked only)
Tier B
CERT-FR12d ago
Vulnérabilité dans les produits Cisco (12 août 2026)
→ No new info (linked only)
Tier D
BleepingComputer12d ago
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
→ No new info (linked only)
Tier A
Cisco Security12d ago
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
→ No new info (linked only)
CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-244
PublishedAug 11, 2026
Trending Score56
Source articles12
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20315
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities
Trending: 42
CRITICALCVE-2026-20357
Cisco Crosswork Security Hardening Release: August 2026
Trending: 39
CRITICALCVE-2026-20030
Cisco Crosswork Security Hardening Release: August 2026
Trending: 39
CRITICALCVE-2026-20317
Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities
Trending: 38
CRITICALCVE-2026-20358
Cisco Crosswork Security Hardening Release: August 2026
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026