Federal agencies had until today to patch a Cisco firewall flaw that is already being exploited

CVE-2026-20349 lets an unauthenticated attacker reboot a Cisco firewall from the internet. It does not steal anything, which is exactly why it is easy to underrate.

The deadline for US federal agencies to patch CVE-2026-20349 was today. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 11 August, which means exploitation has been observed rather than theorised, and gave agencies three days to act.

It affects the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance software and Cisco Secure Firewall Threat Defense software. According to the National Vulnerability Database entry, an unauthenticated remote attacker can send specially crafted HTTP requests that the device mishandles, causing it to reload unexpectedly. The listed CVSS 3.1 base score is 8.6, rated high.

Why a reboot is worse than it sounds

The word that will cause this to be skimmed past is “denial of service”. No data is read, nothing is altered, nothing is exfiltrated. Set against a headline about stolen customer records it reads like a minor operational annoyance.

Consider what the affected component actually does. The Remote Access SSL VPN is the service staff connect through to reach internal systems from outside the building. An attacker who can reliably reboot that device from the internet, without credentials, can take an organisation’s remote workforce offline at a moment of their choosing, repeatedly, for as long as the device stays unpatched.

That has an obvious use as cover. A security team dealing with a firewall that keeps falling over is a security team not looking closely at anything else.

What is affected

The NVD entry lists Cisco Secure Firewall ASA software across versions 9.16.x to 9.20.x, and Secure Firewall Threat Defense software across 7.2.x to 7.4.x. This is enterprise and public sector equipment. If you are reading this at home, you almost certainly do not own one.

That is worth stating plainly, because the interesting question for most readers is not whether to patch their own kit. It is which organisations they depend on are running this hardware, and whether those organisations move at the speed CISA does.

The deadline only binds one group

CISA’s Binding Operational Directive applies to US federal civilian agencies. Everyone else, including every UK company running the same appliance, is being told rather than instructed.

The catalogue is public and free, and it is a better patching queue than a severity score, because inclusion means someone is already using the flaw against real targets. Severity ratings estimate how bad an attack could be. The KEV catalogue records which attacks are actually happening.

For anyone running these appliances the practical step is unchanged from any KEV entry: apply the vendor fix, and check the logs for unexplained reloads before assuming you were not a target.

Sources