WaterISAC is issuing an urgent alert regarding CVE-2026-20349 (CVSS 8.6), a high-severity denial-of-service vulnerability actively being exploited in Cisco Secure Firewall ASA and Threat Defense (FTD) software.
The flaw affects devices running Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access configurations. An unauthenticated remote attacker can send a crafted HTTP request that causes the affected device to reload unexpectedly — knocking out both perimeter security enforcement and remote access simultaneously. No authentication or user interaction is required to exploit the vulnerability. CISA has added it to the Known Exploited Vulnerabilities catalog.