CISA gives federal agencies three days to patch a Cisco firewall flaw already being exploited

Two Cisco Secure Firewall products were added to the US catalogue of actively exploited vulnerabilities on 11 August, with a deadline of 14 August. The short clock is the tell.

Abstract pattern of teal and blue wavy lines
Illustration · Photo by Logan Voss on Unsplash

The US Cybersecurity and Infrastructure Security Agency added a Cisco Secure Firewall vulnerability to its catalogue of actively exploited flaws on 11 August, and gave federal agencies until 14 August to fix it.

Three days is unusually short. Entries in the Known Exploited Vulnerabilities catalogue normally carry a three-week remediation window. When CISA compresses that to a long weekend, it is signalling that the exploitation it has seen is serious enough that the usual timetable does not apply.

What was added

The flaw is tracked as CVE-2026-20349 and affects Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense — ASA and FTD, the software running on a large share of corporate perimeter firewalls.

A second Cisco entry, CVE-2026-20316, covers Secure Firewall Management Center, the console used to administer fleets of those devices.

CISA’s required action points administrators at Cisco’s own mitigation instructions and at the agency’s guidance on prioritising updates by risk. The catalogue lists the ransomware status of CVE-2026-20349 as “Unknown”, which means CISA has confirmed exploitation but has not tied it to a named ransomware operation.

Why a firewall flaw is worse than it sounds

A vulnerability in a firewall is not equivalent to a vulnerability in an ordinary application. The device sits at the network edge, is reachable from the internet by design, and is trusted by everything behind it. It is also the appliance most likely to be left alone for years because rebooting it interrupts everyone.

That combination is why edge appliances have become a favourite target. The compromise does not need to be clever if the device is exposed, unpatched and implicitly trusted.

Cisco separately published an advisory covering a static credential vulnerability in Secure Firewall Management Center on the same day. Static credentials — passwords or keys fixed in the software rather than generated per install — are recurrent in networking kit, and they undermine the assumption that a management console is safe because it sits on an internal network.

What the deadline does and does not mean

The 14 August date is a legal obligation for US federal civilian agencies under Binding Operational Directive 22-01. It does not bind anyone else. No British organisation is required to do anything because a US catalogue entry exists.

The catalogue is still worth watching, because the bar for inclusion is evidence of exploitation in the wild. Most published vulnerabilities never get used against anyone. A KEV entry means somebody is already being attacked with it — which makes the list a far better patching queue than raw severity scores, and it is free to read. We have written a guide to checking your own equipment against the catalogue, including the trick with the due dates.

What to check

If your organisation runs Cisco ASA, FTD or Firewall Management Center, the version numbers in Cisco’s advisories are the authoritative source for whether you are affected. Cisco’s PSIRT advisories name the fixed releases directly, and they are published without a paywall or a login.

We have asked Cisco whether it can say how widely CVE-2026-20349 has been exploited and whether any UK customers are known to be affected. We will update this piece if the company responds.

Sources