[KEV] CVE-2026-20349 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-20349 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-20349 is a remote denial-of-service vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) caused by improper handling during heap inspection.
Technical Detail
An unauthenticated remote attacker could send crafted traffic that triggers the heap inspection flaw on an affected Cisco ASA or FTD device. Successful exploitation can cause the device to reload unexpectedly, resulting in a denial-of-service condition. The available information does not indicate remote code execution, authentication bypass, privilege escalation, or persistent device compromise.
Exploitation Status
CISA has confirmed active exploitation in the wild. Exploit maturity is assessed as Operational, meaning exploitation is considered practical for use in real-world attacks rather than limited to a proof of concept.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize installation of Cisco-provided fixed software for affected ASA and FTD deployments. Review Cisco security advisories and release guidance to identify vulnerable versions and applicable fixed releases. CISA Binding Operational Directive 22-01 requires federal civilian executive branch agencies to patch by September 1, 2026, or apply mitigations. Where immediate patching is not possible, restrict exposure of management and firewall services to trusted networks, limit unnecessary inbound access, and monitor device logs and network telemetry for unexpected reloads, repeated service interruptions, or anomalous traffic preceding a reload. No specific workaround is confirmed in the available data.