Cisco Releases Security Updates for Secure Firewall ASA and Secure Firewall FTD Software
CVE-2026-20349 could allow unauthenticated remote attackers to trigger a denial-of-service condition on affected devices.
Summary
CVE-2026-20349 could allow unauthenticated remote attackers to trigger a denial-of-service condition on affected devices.
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-20349
Cisco has stated vulnerability CVE-2026-20349 has been observed exploited in the wild.
The NHS England National CSOC assesses further exploitation as likely.
Introduction
Cisco has released a security advisory to address a high severity vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software.
- CVE-2026-20349 - "Improper Disposal of Heap-Allocated Memory Before Release" vulnerability - CVSSv3.1 Score: 8.6
Remediation advice
Affected organisations are encouraged to review Cisco advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF and apply the relevant update as soon as possible.
Organisations are encouraged to use the Cisco Software Checker tool to determine the latest available version for their deployment.
Definitive source of threat updates
Last edited: 12 August 2026 2:07 pm