HIGH: Cisco ASA and FTD CVE-2026-20349 Exploited to Crash Firewalls
Cisco confirmed active exploitation of CVE-2026-20349, a CVSS 8.6 flaw in Secure Firewall ASA and Threat Defense software that lets an unauthenticated attacker reboot a VPN gateway with a single crafted HTTP request. CISA added it to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of August 14. There are no workarounds, only patches.