Cisco has confirmed that attackers are already crashing Secure Firewall ASA and Threat Defense devices through their remote-access VPN, and on August 11, 2026 CISA gave federal civilian agencies until August 14 to patch. [1][2] The flaw, CVE-2026-20349, scores 8.6 out of 10 on the CVSS scale, and it steals nothing. [1] An unauthenticated attacker sends one malformed HTTP request to the VPN portal and the firewall reloads. No data leaves, no code runs, the box just falls over, and everyone working through that VPN drops with it. [1][2]
That makes this a different kind of alarm than the breach headlines. A plant in Greensboro does not lose customer records here. It loses its remote access, its site-to-site links, and often its whole internet edge, for as long as an attacker feels like sending the packet.
Run a Cisco ASA or Firepower as your firewall or VPN anywhere in the Piedmont Triad? Ask Preferred Data Corporation to confirm your exposure and patch it before it becomes an after-hours scramble. We are in High Point, on-site within 200 miles, and we have run networks for North Carolina manufacturers since 1987. Call (336) 886-3282.
What does CVE-2026-20349 actually do to a Cisco firewall?
It crashes it, over and over, with no login required. Cisco traced the bug to insufficient error checking when the Remote Access SSL VPN service parses HTTP requests, so a single crafted request forces the appliance to reload into a denial-of-service condition. [1] There is no code execution and no path to your data through this specific flaw, which is exactly why it is easy to underrate and easy to abuse. [1][2]
Three things stack up here. Cisco confirmed its own PSIRT was already seeing this exploited in the wild when it shipped advisory cisco-sa-asaftd-vpn-dos-dzv4mQFF. [1][6] CISA added the CVE to its Known Exploited Vulnerabilities catalog on August 11, 2026 and gave federal civilian agencies until August 14 to fix it, one of the tightest windows it issues. [2][7] And there is no workaround: you patch, or you stay exposed. [6]
Key takeaway: A firewall that only reboots is not a minor bug. The device whose job is to keep your remote sites connected is the device an anonymous attacker can now switch off from anywhere on the internet.
How do you know if your firewall is affected?
Ask whoever manages your firewall two plain questions: does it provide any remote access from the internet, a staff or vendor VPN or Zero Trust Network Access on a Firepower box, and is it already running one of the fixed releases named in Cisco's advisory? If the first answer is yes and the second is no or unknown, treat yourself as exposed until proven otherwise. A patch date alone is not proof, because a box can be moved to another still-vulnerable image; the running version is what settles it. Only devices with one of those remote-access services turned on are affected, and on most NC shop-floor firewalls that remote access is the whole reason the box is there. [1]
For whoever does the actual patching, here is the exact scope. The flaw triggers when an ASA or FTD has SSL VPN enabled, IKEv2 remote-access VPN with client services enabled, or Zero Trust Network Access configured on FTD, with SSL listen sockets active. [1] Cisco Secure Firewall Management Center is not affected. [1] The affected release trains are wide: ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, and FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. [1][6] Cisco fixes each train in a specific maintenance build named in the advisory, so a train number alone is not a verdict; check your exact running version against Cisco's first-fixed list. If none of those remote-access services are turned on, this particular flaw does not apply, though that is worth confirming rather than assuming.
Do not let the "it only crashes" reading calm you down, because the box matters more than the payload. This is the second time in under a year that active exploitation has forced federal action on this exact Cisco firewall family, and the first time was far worse.
| September 2025 (ED 25-03) | August 2026 (CVE-2026-20349) | |
|---|---|---|
| Devices | Cisco ASA and Firepower [3] | Cisco ASA and FTD [1] |
| CVEs | CVE-2025-20333 and CVE-2025-20362 [3] | CVE-2026-20349 [1] |
| Impact | Unauthenticated remote code execution and full takeover, chained [3] | Unauthenticated denial of service, device reload [1] |
| CISA action | Emergency Directive, 24-hour deadline [3] | KEV listing, August 14 deadline [2] |
| Attacker goal | Persist inside the network, survive reboots [3] | Take the device, and your access, offline [1] |
The pattern is the appliance, not the attack. Whatever a Triad shop runs at its network edge, this one internet-facing product line drew a September 2025 Emergency Directive and an August 2026 exploited-in-the-wild listing inside a single year. [1][3]
Already have an IT provider? Forward this to them. Want a second set of eyes before the 14th, or have no network person on call? Confirming your real exposure is a quick, straightforward check for Preferred Data managed network services, not a maybe. Call (336) 886-3282.
Why is a firewall that only crashes still a plant-floor problem?
Because for a manufacturer, availability is the asset, and this attack targets availability directly. A ransomware crew wants your files; a DoS attacker just wants your box down, and the box that goes down is the one carrying your VPN and, usually, your only path onto the internet. When it reloads, the second shift loses the ERP session it opened from the annex, the machine vendor cannot dial in to clear a fault, and the controller you keep on call cannot reach the plant network until the appliance comes back. None of that shows up as a breach, and all of it stops work.
This is the exercise worth running with whoever knows your network: not "what data would we lose," but "what stops moving the second this firewall reboots." For a typical 70-person fabricator the list tends to run longer than the owner would guess: remote order entry, EDI links that ride the VPN, cloud backups that egress through that same edge, and a site-to-site tunnel to a second building across town. An attacker who can reload the firewall on demand holds all of that hostage without ever touching a file.
Key takeaway: Measure this risk in shifts, not records. The question is not whether you would be breached, it is how many hours of production and remote access you lose each time someone decides to knock the appliance over.
What should NC shops do before the August 14 deadline?
Patch the firewall to a fixed Cisco release this week, because there is no workaround and exploitation is already live. [1][2] The federal deadline is not your deadline, but treat it as the calendar an attacker is reading. Here is the order we work in for a client running an exposed ASA or FTD:
- Confirm scope in an hour, not a project. Pull the running version and the enabled VPN features. If one of the remote-access services is on and the running build is not yet one of Cisco's fixed releases, you are in scope. [1][6]
- Schedule the reload, do not wait for one. The upgrade needs a reload, and a single non-HA appliance is offline for VPN and internet the whole time it runs. Size the window from Cisco's upgrade guidance for your specific model, because an FTD image upgrade can run well beyond a quick ASA reboot, and schedule it after hours rather than waiting for an attacker to pick the moment.
- Cross-check the September 2025 fix. If ED 25-03 was ever "patched but still exposed" on this same device, as CISA had to warn about in its November 2025 follow-up, verify the box is genuinely clean before you trust it again. [4]
- Reduce who can reach the portal. Where your operation allows it, restrict the VPN portal to known source ranges so an anonymous scanner on the open internet cannot reach it at all.
- Write down what the reboot breaks. Use the incident as the excuse to finally map which production and remote-access functions ride this one appliance, so the next edge failure is a known quantity.
For a shop without in-house network staff, steps one through three are a same-day engagement. Preferred Data does firewall patching and validation as part of managed IT and monitoring rather than a break-fix visit, so the box that guards your plant is not waiting on someone happening to notice an advisory.
Should a public SSL VPN still be your front door in 2026?
Probably not, and this is the uncomfortable conversation the patch should start. Patching CVE-2026-20349 is mandatory and urgent, but it fixes one bug on an architecture that keeps generating them: a VPN concentrator whose login portal answers every request from the entire internet. A September 2025 Emergency Directive and an August 2026 exploited-in-the-wild listing on the same Cisco firewall family, inside one year, is not bad luck. It is a signal that the always-listening public VPN portal is a shrinking bet. [1][3]
The contrarian position we take with owners is blunt. If your remote-access strategy is a single edge appliance with its SSL VPN exposed to the world, patching faster is not a strategy, it is a treadmill. The design requirement is publishing no public listener for a scanner to reach: cloud-brokered ZTNA that dials out rather than listening on the edge box (not the on-appliance FTD ZTNA this flaw affects), identity-gated access, or a VPN moved behind controls that refuse unknown sources before the firewall parses it. That is a planned migration, not a panic, and it is the difference between reading the next Cisco advisory as a fire drill or as a footnote.
We are not anti-Cisco, and ripping out a working firewall this week to dodge a patch would be its own mistake. The point is sequence: patch now, then put "reduce our dependence on a single internet-facing VPN portal" on the roadmap for this quarter. Preferred Data plans that migration for network and edge security around your maintenance windows across the Triad, so remote access to your plant does not hinge on one box nobody has time to watch.
Want a straight answer on whether your VPN edge is a liability or just a patch behind? Talk to Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265, or call (336) 886-3282. Local, manufacturing-focused, and answering the phone since 1987.
Frequently Asked Questions
Does CVE-2026-20349 mean our data was stolen?
No. This specific vulnerability is a denial-of-service flaw with no code execution and no data access; the impact is that the firewall reloads and drops connections. [1][2] It is an availability problem, not a breach. That said, a firewall you cannot keep online is still a serious operational risk, and the separate September 2025 Cisco ASA flaws were full remote-takeover bugs, so an unpatched edge device is worth a hard look either way. [3]
We have a Cisco ASA but I am not sure the VPN is even on. Are we affected?
Only devices with remote-access VPN features enabled, SSL VPN, IKEv2 remote access with client services, or FTD Zero Trust Network Access, are affected. [1] If none of those are configured, this particular CVE does not apply, but that is exactly the kind of thing worth confirming rather than assuming. Checking the running configuration takes minutes, and it is the first thing we verify for any NC client on a Cisco edge.
Is there a way to block this without rebooting for a patch?
Cisco published no workaround for CVE-2026-20349, so patching to a fixed release is the only fix, and that reload is unavoidable. [1][6] You can lower the odds of being hit in the meantime by restricting which source addresses can reach the VPN portal, but that reduces exposure, it does not remove the vulnerability. Plan the maintenance window and patch.
How fast can this be patched for a shop our size?
For a single firewall it is one scheduled after-hours window: load the fixed Cisco version, reload the appliance, then confirm the new version is running and the box is otherwise clean. How long the reload keeps VPN and internet down depends on the platform and upgrade path, and an FTD image upgrade can run well beyond a quick ASA reboot, so we size the window from Cisco's guidance for your specific model rather than promising a generic number. Preferred Data treats an actively-exploited edge flaw as priority work, scheduled as fast as your operation can take the outage, and we quote it against your actual setup rather than a menu price. Multi-site setups across the Piedmont Triad take a little longer only because each tunnel endpoint gets checked.
Our firewall is old. Should we patch it or replace it?
Patch it now regardless, because a replacement is not happening before August 14. [2] Then have the replacement conversation on its own timeline. If the appliance is near end of support or has outgrown a single public VPN portal, a planned migration to a cloud-brokered access model that publishes no public listener beats buying the same architecture again. We scope that as a project, not an emergency.
Why does this keep happening to Cisco firewalls?
Internet-facing security appliances are high-value targets precisely because they sit at the edge and are trusted, and a VPN portal has to answer unauthenticated requests to function, which is a large attack surface by design. This is the second time in under a year that active exploitation has forced federal action on the ASA and FTD family. [1][3] It is less a Cisco-specific verdict than a reason to question how much of your remote access should depend on any single always-listening edge device.
Related Resources
- Managed Network and Edge Security
- Managed IT and Monitoring for NC Businesses
- Cybersecurity Services
- Backup and Data Protection
- Contact Preferred Data to confirm your Cisco firewall exposure
References
- BleepingComputer. (2026, August 11). Cisco warns of ASA and FTD VPN flaw exploited to crash devices. https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devices/
- The Hacker News. (2026, August). Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS. https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html
- CISA. (2025, September 25). ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices. https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
- CISA. (2025, November 12). Update: Implementation Guidance for Emergency Directive on Cisco ASA and Firepower Device Vulnerabilities. https://www.cisa.gov/news-events/alerts/2025/11/12/update-implementation-guidance-emergency-directive-cisco-asa-and-firepower-device-vulnerabilities
- SecurityWeek. (2026, August). Cisco Patches Firewall Zero-Day Exploited for DoS Attacks. https://www.securityweek.com/cisco-patches-firewall-zero-day-exploited-for-dos-attacks/
- Cisco. (2026). Cisco Secure Firewall ASA and FTD Software Remote Access SSL VPN Denial of Service Vulnerability (cisco-sa-asaftd-vpn-dos-dzv4mQFF). https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF
- CISA. (2026, August 11). CISA Adds Three Known Exploited Vulnerabilities to Catalog. https://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog