Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Russell Westbrook announces NBA retirement after 18 seasons | Basketball News

    August 13, 2026

    Muratov: Putin can no longer claim victory in Ukraine

    August 13, 2026

    Homeland Security Paid $464 Million for Airplanes. Then It Parked Them.

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Russell Westbrook announces NBA retirement after 18 seasons | Basketball News
    • Muratov: Putin can no longer claim victory in Ukraine
    • Homeland Security Paid $464 Million for Airplanes. Then It Parked Them.
    • UK defends seizing shadow fleet tanker after Putin threat
    • Who is Anthropic’s auditor — and why should we care?
    • 5 Best Android Tablets in 2026: OnePlus, Lenovo, and Pixel Compared
    • Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client
    • CEO of Crypto Lender Delio Gets 15 Years Over $49M Fraud
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 12, 2026Network Security / Vulnerability

    Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild.

    The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition.

    “An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device,” Cisco said in a Tuesday advisory. “A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.”

    The security defects impact devices running a vulnerable version of Secure Firewall ASA Software or Cisco Secure FTD Software and have one or more of the vulnerable configurations listed below –

    • IKEv2 Remote Access VPN (with client services) – crypto ikev2 enable client-services port
    • SSL-VPN – webvpn enable
    • Zero Trust Network Access2 – zero-trust enable
    Cybersecurity

    The following versions of ASA and FTD are affected –

    • ASA 9.161 – Fixed in 89.16.4.50)
    • ASA 9.181 – Fixed in 89.18.4.50)
    • ASA 9.20 – Fixed in 9.20.4.235)
    • ASA 9.22 – Fixed in 9.22.3.191)
    • ASA 9.23 – Fixed in 9.23.1.211)
    • ASA 9.24 – Fixed in 9.24.1.221)
    • FTD 7.0 – Fixed in

      • Cisco_FTD_Hotfix_GC-7.0.9.1-1.sh.REL.tar
      • Cisco_FTD_SSP_FP1K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
      • Cisco_FTD_SSP_FP2K_Hotfix_GC-7.0.9.1-1.sh.REL.tar
      • Cisco_FTD_SSP_Hotfix_GC-7.0.9.1-1.sh.REL.tar
    • FTD 7.2 – Fixed in

      • Cisco_FTD_Hotfix_HM-7.2.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP1K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP2K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP3K_Hotfix_HM-7.2.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_Hotfix_HM-7.2.11.1-2.sh.REL.tar
    • FTD 7.4 – Fixed in

      • Cisco_FTD_Hotfix_HK-7.4.7.1-1.sh.REL.tar
      • Cisco_FTD_SSP_FP1K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
      • Cisco_FTD_SSP_FP2K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
      • Cisco_FTD_SSP_FP3K_Hotfix_HK-7.4.7.1-1.sh.REL.tar
      • Cisco_FTD_SSP_Hotfix_HK-7.4.7.1-1.sh.REL.tar
      • Cisco_Secure_FW_TD_4200_Hotfix_HK-7.4.7.1-1.sh.REL.tar
    • FTD 7.6 (Fixed in

      • Cisco_FTD_Hotfix_DD-7.6.4.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP1K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP3K_Hotfix_DD-7.6.4.1-2.sh.REL.tar
      • Cisco_FTD_SSP_Hotfix_DD-7.6.4.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_4200_Hotfix_DD-7.6.4.1-2.sh.REL.tar
    • FTD 7.7 – Fixed in

      • Cisco_FTD_Hotfix_AN-7.7.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP1K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP3K_Hotfix_AN-7.7.11.1-2.sh.REL.tar
      • Cisco_FTD_SSP_Hotfix_AN-7.7.11.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_1200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_4200_Hotfix_AN-7.7.11.1-2.sh.REL.tar
    • FTD 10.0 – Fixed in

      • Cisco_FTD_Hotfix_S-10.0.0.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP1K_Hotfix_S-10.0.0.1-2.sh.REL.tar
      • Cisco_FTD_SSP_FP3K_Hotfix_S-10.0.0.1-2.sh.REL.tar
      • Cisco_FTD_SSP_Hotfix_S-10.0.0.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_200_Hotfix_R-10.0.0.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_1200_Hotfix_S-10.0.0.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_4200_Hotfix_S-10.0.0.1-2.sh.REL.tar
      • Cisco_Secure_FW_TD_6100_Hotfix_S-10.0.0.1-2.sh.REL.tar

    Cisco said there are no workarounds that address the flaw, adding it became aware of active exploitation earlier this month. The network equipment maker said the issue was found during internal security testing. It also credited Valerio Brussani for separately discovering and reporting the vulnerability.

    Cybersecurity

    There are currently no details about the nature of the attacks, the identity and origins of the threat actor exploiting the vulnerability, what organizations have been targeted, and if any of those efforts were successful.

    The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by August 14, 2026.

    ASA Cisco DoS Exploited Flaw FTD remote trigger wild
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

    Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined

    Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

    Liquidity trigger: Hayes watches the Fed’s $60B FIMA cap

    ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

    SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Russell Westbrook announces NBA retirement after 18 seasons | Basketball News

    August 13, 2026

    Muratov: Putin can no longer claim victory in Ukraine

    August 13, 2026

    Homeland Security Paid $464 Million for Airplanes. Then It Parked Them.

    August 13, 2026

    UK defends seizing shadow fleet tanker after Putin threat

    August 13, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Russell Westbrook announces NBA retirement after 18 seasons | Basketball News

    August 13, 2026

    Muratov: Putin can no longer claim victory in Ukraine

    August 13, 2026

    Homeland Security Paid $464 Million for Airplanes. Then It Parked Them.

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.