Yes — since August 11, 2026, CVE-2026-20349 is actively exploited and was added to the CISA KEV catalog with a remediation deadline of August 14, 2026. The vulnerability affects Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) devices with remote access services enabled (SSL VPN / AnyConnect / HTTP management); an unauthenticated attacker can force an unexpected device reload with a single crafted HTTP request. Organizations in telecom/ISP, energy and manufacturing should today confirm their ASA/FTD inventory, disable unneeded endpoints and schedule a maintenance window before 2026-08-14 — a DoS on a CNI edge device means loss of connectivity for customers, branch offices and production lines.
Key facts
- CVE-2026-20349 (CVSS 8.6) was added to the CISA Known Exploited Vulnerabilities catalog on August 11, 2026 with a BOD 26-04 remediation due date of August 14, 2026 — a binding obligation for US federal agencies and a strong urgency signal for the private sector.
- The vulnerability lies in insufficient input validation in the HTTP request handling module of ASA and FTD with remote access services enabled (SSL VPN, AnyConnect, WebVPN); no authentication is required.
- Impact: unexpected device reload (DoS) — not RCE and not data exfiltration; in-the-wild exploit confirmed.
- Affects critical edge devices — in the EU these are deployed in telco/ISP, energy, manufacturing, logistics and public administration as edge firewalls or branch VPN concentrators.
- CISA attached a "Forensics Triage Requirements" — after exploit, the organization must collect logs and indicators of compromise, not just patch.
- Remediation cannot be delayed by "production-critical" arguments — the alternative is temporarily removing the ASA from internet exposure or restricting source traffic, not leaving the CVE open.
Decision table: what we know → what it means for B2B / manufacturing → what to do
| Area | What we know | What it means for a B2B / manufacturing firm | 30-day action | 90-day action |
|---|---|---|---|---|
| ASA/FTD inventory | Cisco public APIs, NetBox, CMDB, SNMP sweep, vendor contracts | If ASA is the branch VPN or edge gateway — it is on the front line | Export ASA/FTD inventory from CMDB; cross-reference with VPN locations | Continuous asset inventory monitoring (class A) + alerts on new ASA/FTD on the network |
| SSL VPN exposure | Every ASA/FTD with WebVPN/AnyConnect/SSL VPN visible from the internet | VPN endpoint is the entry point for thousands of clients/teleworkers — DoS closes the company | `sh run | i WebVPN\ |
| Patch window | CISA dueDate 2026-08-14; patches released by Cisco | Patching ASA in production is risky (restart = session loss) | Scheduled maintenance window no later than 14.08; fallback for critical sites | Standardize a "CISA KEV patch in 14 days" process as an IT KPI |
| Temporary mitigation | Disable WebVPN, ACL on IP, geoblocking, IPS sigs | Partially reduces risk but blocks legitimate users | ACL limiting sources; temporary WebVPN disable where traffic is low | Deploy Cisco IPS / Snort sigs for HTTP DoS; EDR/NDR rules on ASA anomalies |
| Forensics requirement | CISA requires triage after an incident | Without ASA logs you cannot tell if the device was attacked | Enable syslog from ASA to SIEM (auth, VPN, HTTP, reload events) | Log retention min. 90 days; "ASA reload triage" playbook |
| Supply chain and MSP vendor | Many EU operators outsource ASA management to MSP/ISP | An MSP can manage hundreds of ASAs — one KEV record = hundreds of customers at risk | Query MSP vendor about patch status; SLA clause on CISA KEV | Contractual requirement to report KEV within 24h of publication |
| NIS2 / KSC compliance | Art. 21(2)(e) — vulnerability management; Art. 21(2)(c) — continuity | An unpatched DoS on the edge = breach of vulnerability management obligation | Entry in incident/asset register; remediation plan for the board | Deploy CHORS KSC/NIS2 Compliance Program with continuous readiness |
Perspective of Marcin Białczyk (CHORS.NET)
From an operational standpoint, ASA/FTD with SSL VPN is for many Polish B2B companies an "invisible" element: it has been sitting in the server room for years, works, nobody touches it. And that is exactly why a CISA KEV with a 3-day dueDate is so brutal — there is no time for vendor consultations, no time for a five-stage change management, and at the same time touching ASA = restarting VPN sessions for all remote workers and branches. In practice I have seen two reaction patterns: either the company has a ready "CISA KEV patch in 14 days" playbook and then they catch this specific incident within an existing process, or that playbook does not exist and then begins a nervous search for the device owner at 23:00.
At CHORS.NET we treat this type of vulnerability as a classic use-case for the CHORS NIS2/KSC Start or CHORS KSC/NIS2 Compliance Program service — not because we patch the ASA for the client (that is the client's team or the MSP vendor who does it), but because the client needs a rapid view: which ASAs exist, which of them have WebVPN, who is the change owner, whether a maintenance window is scheduled, whether logs flow to SIEM. This is not a "security audit" in a marketing sense — it is an operational audit of the critical edge-device inventory in the context of NIS2 art. 21(2)(e).
Third observation: CVE-2026-20349 is not RCE, so many teams will instinctively postpone it "because no data leaks". That is a mistake — a DoS on a CNI edge device means real operational consequences (loss of B2B customer connectivity, production downtime, unavailability of OT systems), and CISA still classifies such CVEs as KEV with a mandatory deadline. For the board and compliance it should be treated on par with RCE if the ASA sits on a critical path.
Frequently asked questions
1. Does CVE-2026-20349 also affect small ASAs (e.g. ASA 5506-X) in branch offices?
Yes — the vulnerability is in the ASA/FTD software, not the hardware model. Every ASA/FTD with remote access service enabled (SSL VPN / AnyConnect / WebVPN / HTTPS management) is exposed, regardless of size.
2. Can I apply a workaround without patching immediately?
Yes — temporarily you can disable WebVPN on devices where it is not critical, restrict access via ACL to known source IPs, enable IPS/Snort rules for HTTP DoS, and force fail-over to a second device. But this does not waive the patching obligation before 14.08.2026.
3. Are my cloud ASAs (Cisco ASAv / FTDv in AWS/Azure) also at risk?
Yes — the vulnerability is in the software, not the physical location. ASAv/FTDv with remote access services enabled in the public cloud are equally exposed.
4. What if my ASA is managed by an external MSP vendor?
Immediately send a written query (email/ticket) with the link to CISA KEV and a question about the patch plan; agree on a date; request access to ASA logs for triage. No response within 24h = escalation to management and an entry in the vendor risk register.
5. Do I have to report this incident to CSIRT NASK / KSC?
The mere existence of the CVE does not require reporting — what requires reporting is the actual incident (confirmed DoS, exploit, device restart from unknown traffic). If the ASA was restarted by an attacker, it is a security incident and requires assessment of the severity threshold (NIS2 art. 23, KSC art. 11).
How CHORS.NET helps
CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.
Boundaries and assumptions
- We are not a SOC 24/7 and we do not guarantee detection of every incident.
- We do not certify NIS2/KSC compliance and we do not issue an independent legal opinion.
- Results reflect the state at the time of the article (2026-08-11).
- For legal interpretation of NIS2/KSC, CHORS works with law firms.
- This material is informational and technical; it is not legal advice and not a guarantee of security.
- There is no claim of "full compliance", a "compliance certificate" or "guarantee of detection" here — these are formulations we deliberately do not use.
Sources
- CISA Known Exploited Vulnerabilities Catalog
- CISA Cybersecurity Advisory — CISA adds three known exploited vulnerabilities to catalog (2026-08-11)
- BleepingComputer — Cisco warns of ASA and FTD VPN flaw exploited to crash devices
- Cisco Security Advisories — Cisco Secure Firewall ASA / FTD official advisory (cisco.com)
- NVD — CVE-2026-20349 entry (nvd.nist.gov)
- ENISA — Vulnerability Management guidance
- NIS2 Directive (EU 2022/2555), art. 21(2)(e) and art. 23
Footer
Author: Marcin Białczyk, Founder & Cybersecurity Operator at CHORS.NET Updated: 2026-08-11