Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Cisco Firewall Vulnerability Could Cause Service Disruptions

A serious security flaw has been found in Cisco's Secure Firewall devices that could allow attackers to remotely crash the firewall, causing network outages. This is important because many small businesses use these firewalls to protect their networks and remote access.

12 August 2026

Reference: CVE-2026-20349

1. What is being reported?

The vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) products. It allows an attacker to send a specially crafted request to the firewall’s remote access VPN service, causing the device to unexpectedly restart. This results in a denial of service, meaning the firewall stops working temporarily.

2. What this means in plain English

If your organisation uses these Cisco firewalls for remote VPN access, an attacker could disrupt your network by causing the firewall to crash. This could prevent staff from connecting remotely and leave your network unprotected until the device restarts and recovers.

3. Could this affect a small business?

Small businesses using Cisco ASA or FTD firewalls with remote access VPN services could be affected, especially if these devices are exposed to the internet. Organisations not using these specific Cisco products or not offering remote VPN access are unlikely to be affected.

4. What to do now

  • Check if your organisation uses Cisco Secure Firewall ASA or FTD devices with remote access VPN.
  • Ask your IT provider if the devices have been updated with the latest security patches from Cisco.
  • If patches are not yet available, follow any temporary mitigations recommended by Cisco or your IT provider.
  • Ensure your firewall devices are not unnecessarily exposed to the internet and monitor for unusual activity.

5. Ask your IT provider

Can you confirm whether our Cisco Secure Firewall ASA or FTD devices are patched against the CVE-2026-20349 vulnerability and what mitigations are in place to prevent service disruption?

6. Bottom line

Make sure your Cisco firewall devices are updated promptly to avoid potential network outages caused by this known vulnerability.

Information based on CISA KEV, NVD and multiple reputable security reports.

Back to Vulnerability Briefs