Cookie Consent by Free Privacy Policy Generator

Cisco patches firewall zero-day exploited for denial of service attacks

Cisco has released patches for a zero-day vulnerability in its Secure Firewall ASA and Firepower Threat Defense (FTD) devices that has been exploited in denial of service attacks. The vulnerability, tracked as CVE-2026-20349, can be exploited remotely without authentication. The flaw allows an attacker to cause the firewall to reload, resulting in a denial of service condition. Cisco has confirmed that the vulnerability is being actively exploited, though the company has not disclosed details about the scope or targeting of the attacks. The patches are available now for affected ASA and FTD software versions.

Why this matters for UK organisations

For UK organisations using Cisco firewalls at the network perimeter, this represents a direct operational risk. Firewalls that can be remotely crashed without authentication create an availability problem that attackers can exploit either for disruption or as part of a broader attack sequence. The fact that this vulnerability is already being exploited means that proof-of-concept code or exploitation techniques are likely in circulation. Organisations should assume that any internet-facing Cisco ASA or FTD device is a potential target. The remote, unauthenticated nature of the vulnerability means that traditional perimeter controls will not prevent exploitation, the patch is the primary mitigation. Denial of service attacks on perimeter firewalls can have cascading effects on business operations, particularly for organisations that rely on VPN access for remote workers or that have critical services sitting behind the affected devices. Even temporary unavailability of a perimeter firewall can disrupt operations, trigger incident response processes, and create uncertainty about whether the denial of service is masking other malicious activity.

What to review

Organisations should prioritise patching of internet-facing Cisco ASA and FTD devices. Where immediate patching is not possible due to change control processes or operational constraints, organisations should review monitoring for unexpected firewall reboots and ensure that firewall availability is being tracked as part of operational monitoring. Repeated exploitation could indicate targeting or reconnaissance activity, and may be a precursor to more sophisticated attacks. It is also worth reviewing whether you have sufficient redundancy and failover capability to maintain connectivity if a perimeter firewall is taken offline, either through exploitation or during emergency patching. For organisations with multiple sites or distributed infrastructure, consider whether a coordinated denial of service attack against multiple firewalls could create a wider operational impact. This is also a useful prompt to review whether perimeter devices are included in your vulnerability management processes with the same priority as internal systems, and whether you have clear processes for emergency patching of internet-facing infrastructure when actively exploited zero-days are disclosed.

Source: SecurityWeek

News and blog posts
The North Korean threat actor known as Lazarus Group has exploited a Windows...
Israeli cybersecurity firm Dream has reported observing what appears to be the...
Today's brief highlights practical developments across governance,...
The NCSC has added a water sector example to its Secure Connectivity Principles...