Skip to main content

Cisco Releases Security Updates for Secure Firewall ASA and Secure Firewall FTD Software

CVE-2026-20349 could allow unauthenticated remote attackers to trigger a denial-of-service condition on affected devices.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-20349 could allow unauthenticated remote attackers to trigger a denial-of-service condition on affected devices.


Affected platforms

The following platforms are known to be affected:

Threat details

Exploitation of CVE-2026-20349

Cisco has stated vulnerability CVE-2026-20349 has been observed exploited in the wild.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Cisco has released a security advisory to address a high severity vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software.

  • CVE-2026-20349 - "Improper Disposal of Heap-Allocated Memory Before Release" vulnerability - CVSSv3.1 Score: 8.6

Remediation advice

Affected organisations are encouraged to review Cisco advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF and apply the relevant update as soon as possible.

Organisations are encouraged to use the Cisco Software Checker tool to determine the latest available version for their deployment.



Last edited: 12 August 2026 2:07 pm