CVE-2026-20349 · Low · CISA KEV

Cisco Secure Firewall DoS Vulnerability Actively Exploited in the Wild

Threat Engine Auto-Feed · data current as of 2026-08-12

A heap inspection vulnerability in Cisco Secure Firewall ASA and FTD can lead to unexpected device reloads and denial of service. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA KEV.

  • CVSS:
  • EPSS percentile:
  • Exploitation pressure: 25/100 (Low)

Exploitation reality: listed in CISA KEV (exploited in the wild). Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves a flaw in how the firewall processes or inspects data in its memory (heap). An attacker can exploit this to corrupt the memory, causing the device to crash and restart, leading to a denial of service.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations relying on Cisco Secure Firewall ASA or FTD for critical network perimeter defense
  • Financial services organizations targeted by FIN7, LockBit affiliates, and APT38
  • Technology companies targeted by APT29 and Scattered Spider

Misconfigurations that escalate it

  • Lack of robust monitoring for unexpected firewall reloads or service interruptions
  • Insufficient redundancy or failover mechanisms for critical network security devices

High-impact scenarios

  • Network service disruption due to firewall reloads, impacting business operations and connectivity
  • Temporary loss of security enforcement, potentially creating windows for further compromise if not quickly addressed

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor Cisco Secure Firewall ASA and FTD devices for unexpected reloads or crashes
  • Review device logs for indicators of heap inspection anomalies or denial of service events

Contain

  • Isolate affected devices if reloads are observed to prevent further impact, if feasible without compromising overall network security

Patch

  • Apply vendor-provided security patches for Cisco Secure Firewall ASA and FTD as soon as they become available

Frontier verdict — Low

High priority due to active exploitation in the wild, leading to denial of service in critical network security infrastructure.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.