HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical DoS Vulnerability in Cisco Secure Firewall ASA & FTD (CVE‑2026‑20349) Enables Unauthenticated Service Disruption

Cisco’s Remote Access SSL VPN service in ASA and FTD appliances is being actively exploited to cause denial‑of‑service without authentication. The flaw threatens availability controls required for SOC 2 compliance, making rapid patching essential for audit readiness.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Critical DoS Vulnerability in Cisco Secure Firewall ASA & FTD (CVE‑2026‑20349) Enables Unauthenticated Service Disruption

What It Is – A high‑severity flaw in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) allows an attacker to send a crafted HTTP request that forces the appliance to reload, causing a denial‑of‑service condition.

Exploitability – Actively exploited in the wild; attackers need no credentials or user interaction. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog and must be patched by U.S. civilian agencies by 14 Aug 2026. CVSS ≥ 7.5 (high).

Affected Products – Cisco Secure Firewall ASA (software 9.16‑9.24) and Cisco Secure Firewall FTD (software 7.0‑7.7, 10.0) when IKEv2 Remote Access VPN, SSL VPN, or ZTNA features are enabled.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (System Operations) requires documented evidence that critical security services are continuously monitored and that known vulnerabilities are remediated promptly.
  • Unpatched DoS flaws can trigger service‑availability exceptions, jeopardizing the “Availability” trust principle and audit attestations.
  • Mapping this vulnerability to a control‑gap view provides concrete audit evidence of due‑diligence and supports continuous compliance reporting.

Recommended Actions

  • Verify current ASA/FTD software versions against Cisco’s hot‑fix list (9.16‑9.24 for ASA; 7.0‑7.7, 10.0 for FTD).
  • Apply the released hot‑fixes immediately; there are no work‑arounds.
  • If SSL VPN/ZTNA features are not required, disable the associated listen sockets to reduce attack surface.
  • Update your asset inventory and vulnerability‑management dashboard to flag CVE‑2026‑20349 as a high‑priority remediation item.
  • Map the remediation to SOC 2 control CC6.1 and capture patch‑deployment logs as audit evidence.

Source: Help Net Security – Cisco fixes vulnerability exploited to DoS its firewalls (CVE‑2026‑20349)

📰 Original Source
https://www.helpnetsecurity.com/2026/08/13/cve-2026-20349-cisco-firewalls-dos/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →