Skip to main content

Cisco ASA and Firepower FTD VPN Denial of Service Under Active Exploitation (CVE-2026-20349)

Scope: Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) with Remote Access SSL VPN Enabled

Severity: High

Cisco confirmed today, August 13, 2026, that CVE-2026-20349, a denial of service vulnerability in the Remote Access SSL VPN service of Cisco ASA and Firepower FTD appliances, is under active exploitation in the wild with no patch yet available. Unauthenticated remote attackers can crash affected devices by sending a single crafted HTTP request to the SSL VPN service, forcing a device reload and taking the VPN offline and disrupting remote access for all connected users. Cisco ASA and FTD appliances are widely deployed as enterprise perimeter security and VPN gateways across Ugandan government and private sector environments, making a successful denial of service attack a direct disruption to remote workforce access and site-to-site connectivity. As no patch exists yet, organizations must immediately restrict internet-facing exposure of the Remote Access SSL VPN service and monitor Cisco's PSIRT page for patch availability.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.