CVE-2026-20349
Cisco ASA/FTD Remote Access SSL VPN unauthenticated reload - a single crafted HTTP request takes the VPN down (CVSS 8.6, KEV 2026-08-12)
- Severity
- high
- Affected product
- Cisco ASA/FTD WebVPN
- Affected versions
- Cisco ASA/FTD WebVPN all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-12
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Cisco ASA/FTD WebVPN appliance and reports this CVE when the detected version falls inside the affected range below.
cisco-sa-asaftd-vpn-dos-dzv4mQFF: insufficient error checking while parsing an HTTP request on the RA SSL VPN service, so an unauthenticated remote attacker reloads the device - on a perimeter firewall that is the remote-access path for the whole workforce, which is why an 8.6 DoS is on KEV. Advisory observation on the fingerprint, and DELIBERATELY never probed: the proof of this bug IS the outage, so a scanner that confirmed it would be the attack. No version gate, same as the two rows above - the fix ships as per-train releases (9.16.x/9.17.x/9.18.x ... FTD 7.x) that the logon page does not disclose.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →