Heap Inspection in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2026-20349
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to insufficient error checking in the Remote Access SSL VPN service when processing HTTP requests. A remote attacker can send a crafted HTTP request to cause a denial of service.
The issue can cause the affected device to reload unexpectedly.
Note, the vulnerability is being exploited in the wild.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2026-20349
Cisco Adaptive Security Appliance (ASA) - addressed in versions 9.16 89.18.4.50, 9.18 89.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221