boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-20349HIGH
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  N  N  H    8.6   .0087   56.1   YES
AFFECTED
  Product                                                           Versions  Fixed
  Cisco Secure Firewall Adaptive Security Appliance (ASA) Software  9.16.1 –  —
  Cisco Secure Firewall Threat Defense (FTD) Software               7.0.0 –   —
TIMELINE
  Oct 8   Reserved by cisco
  Aug 11  Added to CISA KEV, remediation due 2026-08-14
  Aug 11  Published (CNA: cisco)
  Aug 15  DUE DATE PASSED — CVE-2026-20349 (Cisco Secure Firewall Adaptive Security Appliance (ASA) Software). CISA remediation deadline was August 14, 2026; still in catalog.
CWE-244 · CNA: cisco · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due August 14, 2026

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
October 8, 2025ReservedReserved by cisco
August 11, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-08-14
August 11, 2026PublishedPublished (CNA: cisco)
August 15, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2026-20349 (Cisco Secure Firewall Adaptive Security Appliance (ASA) Software). CISA remediation deadline was August 14, 2026; still in catalog.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) Software9.16.1
CiscoCisco Secure Firewall Threat Defense (FTD) Software7.0.0

Weaknesses

CWE-244

References (2)

Related

Authoritative record: CVE-2026-20349 at cve.org

Vendors: cisco

Weaknesses: CWE-244

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-20349 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.