Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

8/13/2026 • Security

A Cisco firewall zero-day is crashing VPNs — here's the plan

Attackers are actively exploiting an unauthenticated flaw (CVE-2026-20349) that lets them crash Cisco ASA and FTD firewalls through the Remote Access SSL VPN. Here's what it really means and the calm, no-upsell steps to take.

A quick heads-up from us to you: there's a Cisco firewall flaw doing the rounds right now that's worth a few minutes of your attention. It's the kind of thing we keep an eye on so you don't have to — and this one is being exploited in the wild, so it earns a post.

The short version: an attacker on the internet can send one specially crafted web request to certain Cisco firewalls and make the device restart — knocking your remote-access VPN, and often your whole internet connection, offline while it reboots. No password required. Cisco has released fixes, and there is no workaround, so the action here is straightforward. Let's walk through it calmly.

What happened, in plain English

The flaw is tracked as CVE-2026-20349. It affects Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defense (FTD) software — the platforms behind a lot of business firewalls and VPN concentrators.

It lives in the Remote Access SSL VPN service (the bit that lets staff dial in from home or the road). Because the firewall does "insufficient error checking" when it processes certain HTTP requests, an unauthenticated, remote attacker can send a malformed request and cause the device to reload unexpectedly. That's a denial-of-service (DoS): while the box reboots, your VPN drops and, in most deployments, so does the traffic passing through it.

Here's the honest nuance, because getting this right is the whole point of these posts:

  • It's a crash, not a break-in. Cisco and the U.S. National Vulnerability Database both rate the impact as availability only — no data is read, no code is run, nothing is stolen. The CVSS vector (C:N/I:N/A:H) confirms it: the risk is downtime, not a breach. That's genuinely less alarming than an "unauthenticated RCE" headline, and we're not going to dress it up as one.
  • But it's rated 8.6 (High), and it's being exploited. Cisco's Product Security Incident Response Team confirmed it became aware of active exploitation in August 2026, and CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 11 August 2026, giving U.S. federal agencies until 14 August to patch. When something is on the KEV list, "we'll get to it next quarter" is the wrong answer.
  • No password needed. The PR:N in the CVSS vector means an attacker doesn't need any credentials — just network reach to your VPN's public-facing login page. If your VPN is on the internet (it usually is, that's the point of it), it's reachable.
  • The affected services are broader than just SSL VPN. Cisco notes devices are exposed if they have SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.

Why it matters — the real lesson

It's easy to shrug at "it just reboots." But think about what reboots. This is the firewall — the thing guarding the door to everything else, and the thing your remote workers rely on to get in at all. An attacker who can restart it at will can:

  • knock your team's VPN offline repeatedly during business hours,
  • interrupt whatever traffic flows through that firewall, and
  • do it over and over, from anywhere, with no login.

For a small business running a hybrid or remote team, a VPN that keeps dropping isn't a minor annoyance — it's the day grinding to a halt. The broader lesson is one we keep coming back to: the security appliance itself is an attack surface. The box you bought to protect the network is software too, and software has bugs. That's not a reason to distrust firewalls; it's a reason to patch them like you'd patch anything else exposed to the internet — promptly, and on a plan.

The honest bit

This is Cisco kit, and Cisco is a brand we like and sell. No spin: no vendor is immune, including the ones we recommend. What actually matters is how a vendor behaves when a flaw turns up — and here the story is reassuring. Cisco found this during its own internal security testing, disclosed it clearly, published fixed releases across the affected versions, and was upfront that exploitation was already happening. That's the mature-vendor response you want to see. It's the quiet ones you worry about — remember the router backdoor we covered where the vendor said nothing.

One genuine, non-salesy difference worth noting: with cloud-managed firewalls, fixes for issues like this are often staged and pushed for you, and your end-of-support dates are visible and plannable rather than a surprise. We wrote about that upside separately — why a cloud-managed firewall keeps getting better after you buy it — and it's a real advantage here, not a pitch. Self-managed ASA/FTD gives you more control; the trade-off is that patching promptly is on you.

What we'd suggest you actually do

No upsell — just the checklist:

  1. Find out if you're affected. Do you run a Cisco ASA or Firepower/FTD firewall with Remote Access VPN (SSL VPN, IKEv2 with client services, or ZTNA) enabled? If yes, you're in scope. If you're not sure, that uncertainty is itself worth resolving.
  2. Apply Cisco's fix. Cisco has released fixed software (hotfixes span ASA 9.16 through 9.24 and FTD 7.0 through 10.0). There is no workaround — patching is the only real remedy. Check the advisory for the exact fixed release for your platform and version.
  3. Prioritise anything internet-facing. A VPN endpoint is, by definition, exposed. Treat those boxes first.
  4. If you genuinely can't patch immediately, weigh whether the remote-access VPN service needs to be reachable from the whole internet right now, or whether you can restrict/disable it briefly until the update lands. (This is a stopgap, not a fix.)
  5. Do the boring basics while you're in there. Confirm admin interfaces aren't needlessly exposed, default credentials are gone, and multi-factor authentication is on for VPN logins. None of that stops this specific crash, but it's exactly the hygiene that limits the next issue.
  6. Write down your patch plan. If applying a firewall update means a scheduled reboot and a maintenance window, decide now who does it and when — so the next KEV-listed flaw isn't a scramble.

The friendly takeaway

This one is refreshingly clear-cut: it's a crash, not a breach; it's being exploited; there's a patch; there's no workaround. If you run Cisco ASA or FTD with remote-access VPN, get the update scheduled — sooner rather than later, given it's on CISA's exploited list. If you don't run Cisco firewalls, the takeaway still holds: the appliance protecting your network needs patching just like everything else, and knowing which of your gear can still receive fixes is half the battle. We touched on that in our note on planning a firewall refresh before support runs out, and on whether your network could even spot an intruder.

If you'd like a second pair of eyes on your firewall — what you're running, whether it's still supported, and whether it's exposed — we're happy to take a look. No hard sell, no obligation. That's just us watching out for you.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.