Cisco Firewall Flaw Being Actively Exploited to Crash Devices
Cisco has issued a warning about a newly disclosed vulnerability affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, confirming it is already being exploited by attackers. Tracked as CVE-2026-20349 and rated 8.6 out of 10 for severity, the flaw stems from insufficient error checking when the software processes certain HTTP requests.
Because the vulnerability can be triggered without authentication, a remote attacker could send specially crafted requests to a vulnerable device and cause it to crash or stop responding — a denial-of-service (DoS) condition. For businesses relying on these firewalls to protect their network perimeter, this could mean a sudden loss of protection or connectivity, potentially at the worst possible time if timed with a broader attack.
Cisco firewalls are widely used by organisations of all sizes, including many Australian businesses and the managed service providers that support them. Given that exploitation is already occurring in the wild, patching should be treated as urgent rather than routine maintenance.