Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

🚨SEVERITY: HIGH — CVSS 8.6Security Advisory

TL;DR 📌

  • Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
  • Highest CVSS: 8.6 (High).
  • Listed in CISA KEV (2026-08-11) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-20349.

What it is

CVE-2026-20349 is a heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw sits in the code handling heap memory on affected devices.

An attacker needs no credentials and can reach the vulnerability over the network, per the CVSS vector (AV:N, PR:N, UI:N). This points to a data-plane or externally reachable process rather than a management-only interface, though the advisory should be consulted for the precise traffic or feature that triggers it.

Successful exploitation causes the device to reload, producing a denial of service. The CVSS scoring (C:N/I:N/A:H) confirms this is an availability impact only — there is no indication of data disclosure or integrity loss. The score of 8.6 (High) reflects the ease of remote, unauthenticated triggering combined with the impact of an unplanned reload on a firewall.

This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-08-11, meaning it is known to be exploited.

What to do

  • Treat this as a priority patching item given its KEV status and unauthenticated remote trigger on firewall infrastructure.
  • Check Cisco’s advisory for fixed software releases covering your specific ASA or FTD version — none were available at the time of this brief, so consult the advisory directly for current guidance.
  • Where a fix isn’t yet available for your version, review Cisco’s advisory for any interim mitigations or workarounds before assuming none exist.
  • Confirm which devices in your estate run ASA or FTD and prioritise those exposed to untrusted networks.
  • Once a fix is published, plan for a device reload during the maintenance window, since applying the update itself may require a restart.
  • Monitor for unexpected reloads on affected devices in the meantime, as these may indicate active triggering of this condition.

For leadership 🧭

Executive summary. Cisco ASA and FTD firewalls can be forced to reload by a remote attacker with no credentials, and this is already being exploited according to CISA’s KEV listing. Given the perimeter role these devices play, this needs urgent attention rather than routine patch-cycle treatment.

Why it matters:

  • The flaw is remotely triggerable without authentication (AV:N, PR:N, UI:N), meaning any attacker who can reach the device’s network-facing service can attempt it.
  • Successful exploitation reloads the ASA or FTD appliance, which typically sits at the network edge, so a reload can disrupt inbound and outbound traffic for everything behind it.
  • CISA added this to its Known Exploited Vulnerabilities catalogue on 2026-08-11, confirming exploitation activity rather than theoretical risk.
  • The impact is availability-only (C:N/I:N/A:H) — no data theft or tampering indicated — but repeated forced reloads on firewall infrastructure still translate into real outages.

Now / Next / Later:

  • Now: Identify every ASA and FTD device in your estate, note which are reachable from untrusted networks, and check Cisco’s advisory for fixed releases and any interim workarounds for your specific version.
  • Next: Schedule and apply the fixed software release during a maintenance window, planning for the device reload the update itself will require.
  • Later: Build routine tracking of Cisco’s ASA/FTD advisories into your patch process and monitor affected devices for unexpected reloads that could indicate active triggering before a fix is applied.

Source