Hackers could exploit a vulnerability in Cisco firewalls’ software to crash the devices, the networking giant is warning customers.
The flaw, tracked as CVE-2026-20349, “could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition,” Cisco said in a Tuesday advisory.
Devices running two Cisco operating systems, Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD), are vulnerable to CVE-2026-20349, which stems from the software’s failure to properly check for errors when processing HTTP requests. Hackers could take advantage of that failure by sending error-riddled HTTP requests to the firewalls through their remote-access connections.
Cisco released fixes for multiple versions of the ASA and FTD software and said it “strongly recommends” that customers upgrade to those versions.
The Cybersecurity and Infrastructure Security Agency (CISA) immediately added the flaw to its Known Exploited Vulnerabilities catalog, indicating that hackers have quickly begun to take advantage of the flaw to target Cisco networking devices. Federal agencies have until Aug. 14 to upgrade affected devices.
Cisco devices have faced a wide range of cyberattacks in recent years, with the ASA and FTD operating systems producing repeated vulnerabilities.
In September 2025, CISA issued an emergency directive warning agencies to patch high-severity bugs in Cisco devices running ASA. A U.S. official said at the time that the highly sophisticated campaign had already compromised at least 10 organizations around the world, and nearly 50,000 devices were revealed to be vulnerable. The incident prompted questions from lawmakers about how seriously Cisco, a market leader in networking devices, was taking its products’ cybersecurity.