EXPOSURES › CVE-2026-20349
CVE-2026-20349
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA/FTD devices have an unpatched heap inspection vulnerability allowing remote denial of service.
An unauthenticated remote attacker can cause Cisco ASA and FTD firewalls to reload unexpectedly, resulting in a denial of service. This is a known, actively exploited vulnerability (KEV) that DIB organizations must urgently patch to prevent network outages and maintain compliance with security baselines.
Shame score — The vulnerability is actively exploited in the wild and affects critical network infrastructure, yet remains unpatched for many devices, demonstrating a failure in timely patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
| PRODUCT | STATUS |
|---|---|
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |