Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status

Cisco Firewall Flaw Under Active Attack: Update Now

If your business runs a Cisco firewall or VPN gateway, this one needs attention today.

A vulnerability tracked as CVE-2026-20349 has been confirmed as actively exploited in the wild. It affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) software – two of the most widely deployed firewall and remote-access VPN platforms in the UK business market. The US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalogue on 11 August 2026. Cisco has now released patched software, and no workarounds exist: applying the update is the only way to resolve this.

What the vulnerability does

The flaw sits in the Remote Access SSL VPN service on these devices. An unauthenticated attacker – one who needs no username, password, or credentials of any kind – can send a specially crafted HTTP request to an internet-facing Cisco device and force it to restart unexpectedly.

That restart takes your firewall offline. Depending on your network setup, the impact could range from losing VPN connectivity for remote workers to a complete loss of internet access across your site. This type of attack is known as a denial of service (DoS) condition: the attacker’s goal is not to steal data but to knock your defences out. In ransomware campaigns, attackers sometimes use DoS conditions against perimeter devices to create a window in which to move through a network undetected.

The vulnerability carries a CVSS score of 8.6 out of 10, placing it firmly in the “high” severity category.

Which devices are affected

If you are running any of the following, you are potentially exposed:

  • Cisco Secure Firewall ASA software – versions 9.16 through 9.24, with Remote Access SSL VPN enabled
  • Cisco Secure Firewall Threat Defense (FTD) software – versions 7.0 through 10.0, with Remote Access SSL VPN enabled

The critical factor is whether SSL VPN or IKEv2 Remote Access VPN is enabled on the device. If your Cisco firewall is not configured to offer remote-access VPN, your exposure is significantly reduced – but it is still worth verifying, as many devices have VPN features enabled by default or switched on during an earlier setup and never reviewed.

What to do now

Cisco has released patched software versions. There is no vendor-supported workaround: applying the update is the only way to fully resolve the issue. Here is the suggested order of action:

  1. Identify your Cisco appliances. List any Cisco ASA or FTD devices in use and confirm the current software version running on each.
  2. Apply Cisco’s fixed software. Cisco’s Product Security Incident Response Team (PSIRT) has published a full advisory with version-by-version patching guidance. Search the Cisco website for the advisory covering CVE-2026-20349 and download the appropriate release for your model.
  3. Review recent restart logs. Check firewall event logs for any unexpected device reloads over the past three to four weeks. An unexplained restart may indicate an exploitation attempt has already occurred.
  4. Confirm whether SSL VPN is genuinely required. If Remote Access SSL VPN is enabled but not actively used, consider disabling the feature at the perimeter while the patch is arranged.

A note for SFIT managed clients

System Force IT’s managed clients use Fortinet firewalls and VPN as standard, which are not affected by CVE-2026-20349. However, if your organisation has any Cisco ASA or FTD devices in your environment – as a secondary appliance, a legacy piece of kit, or part of a hybrid setup inherited from a previous provider – please let us know and we will check your configuration and help arrange the update.

If you are managing Cisco devices outside a support agreement, this is the moment to act. Our managed IT support team can assess your exposure, confirm which versions need updating, and help you get protected quickly.

Why this matters beyond the patch

Firewalls and VPN gateways are the front door to your network. A flaw that lets an unauthenticated attacker crash them remotely – with no credentials required – is precisely the kind of vulnerability that gets picked up quickly by opportunistic attackers once it becomes publicly known. CISA’s inclusion of CVE-2026-20349 in their Known Exploited Vulnerabilities catalogue is confirmation that exploitation is already happening, not a theoretical future risk.

If you would like an independent review of your network perimeter or want practical IT advice on your firewall setup, we are happy to help. Call us on 01452 701355 or visit systemforce.co.uk/contact/ for a no-obligation conversation.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name