ZeroDayAlert

CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Added to KEV 2026-08-11 Federal due 2026-08-14 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) devices. An unauthenticated remote attacker can trigger a heap inspection flaw that causes the device to reload unexpectedly, creating a denial of service condition. The record does not specify affected software versions or deployment configurations.

How to check whether this touches you

  • Inventory all Cisco Secure Firewall ASA and FTD appliances in your organisation, including virtual instances.
  • Confirm whether each device is reachable from the internet or from untrusted networks; devices isolated to trusted internal segments carry lower risk.
  • Check the running software version on each device via the CLI (show version) or management interface; version alone does not confirm mitigation status, as Cisco may have backported fixes into earlier releases.
  • Review Cisco's security advisory for this CVE to determine which versions contain the patch and whether your deployment falls within the affected range.

What to do

  1. If you cannot patch immediately, prioritise devices that face the internet or untrusted networks for additional monitoring and network segmentation review.
  2. Consult Cisco's published advisory to identify the patched software version(s) and plan a maintenance window for deployment; coordinate with your change management process.
  3. Apply the vendor patch in accordance with Cisco's instructions and CISA's BOD 26-04 guidance on patching timelines for internet-facing assets.
  4. If mitigations are unavailable for your device model or software version, evaluate discontinuation of the product or enhanced network controls as alternatives.
  5. Enable and review device reload logs and syslog output during and after patching to confirm successful remediation and detect any unexpected reloads.

If you find you were exposed

Exploitation typically precedes public disclosure; check device logs and syslog archives for unexpected reloads or crashes in the weeks before the advisory date. Correlate reload timestamps with external traffic patterns and any suspicious connection attempts. Confirm log retention policies cover at least 90 days; if logs have been overwritten, document the gap and use this as input to your log retention review.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-20349 is being exploited. It cannot tell you whether Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →