Cisco is warning customers that a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software is being exploited to crash affected devices, according to BleepingComputer’s report on Cisco’s advisory. The flaw is tracked as CVE-2026-20349 and carries a severity score of 8.6. BleepingComputer reports that it affects devices running Cisco Secure Firewall ASA or Secure Firewall FTD software when certain remote access services are enabled. Cisco’s advisory attributes the issue to insufficient error checking while the software processes HTTP requests, according to the report. An unauthenticated remote attacker can exploit the bug by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. If successful, the attack can force the device to reload, creating a denial-of-service condition. The exposure depends on configuration. BleepingComputer reports that vulnerable setups include IKEv2 Remote Access VPN with client services, SSL VPN, and Zero Trust Network Access on FTD devices. Cisco Secure Firewall Management Center software is not affected, according to the same report. Cisco has released hot fixes for affected ASA 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 releases, as well as FTD 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 releases. The company says there are no workarounds and is advising customers to upgrade to a fixed release to fully remediate the issue. BleepingComputer reports that Cisco’s Product Security Incident Response Team became aware of active exploitation of CVE-2026-20349 in August 2026. Cisco has not disclosed who is exploiting the vulnerability, what organizations are being targeted, or indicators of compromise tied to the attacks. The report also says the vulnerability was found during Cisco internal security testing and was independently reported to the company by security researcher Valerio Brussani. For operators, the immediate action is narrower than a broad product-line review but still urgent: identify ASA and FTD deployments with the listed remote access services enabled, then map those systems to the fixed release trains Cisco has published. Who benefits: Attackers benefit from an unauthenticated remote path to crash exposed devices. Defenders benefit from the fact that Cisco has named the affected configurations and released hot fixes for specific ASA and FTD release trains. Who's exposed: Organizations running affected Cisco Secure Firewall ASA or FTD software with the listed remote access services enabled are exposed. Cisco Secure Firewall Management Center is not affected, according to the report.