Cisco Fixes Actively Exploited Firewall Flaw That Can Knock Devices Offline
Cisco has released patches for a serious security flaw, tracked as CVE-2026-20349, affecting its Secure Firewall ASA and FTD (Firepower Threat Defense) devices. The vulnerability could be exploited remotely by attackers without needing any login credentials, making it especially dangerous. Exploiting the flaw allows attackers to trigger a denial-of-service (DoS) condition, effectively crashing or disabling the firewall.
Firewalls are a core line of defence for businesses, filtering malicious traffic and protecting internal networks. If a firewall is knocked offline, it can disrupt business operations and, depending on configuration, potentially leave a network more exposed while the device is down or being restored. Cisco has confirmed the vulnerability was already being exploited in the wild before the patch was released, underlining the urgency for organisations using affected devices to update as soon as possible.
Any Australian small business relying on Cisco Secure Firewall ASA or FTD appliances, whether managed in-house or through an IT provider, should treat this as a priority update. Delaying patching leaves a critical piece of security infrastructure open to disruption from remote, unauthenticated attackers.