CVE-2026-20349 takes Cisco firewall VPNs offline with a single unauthenticated HTTP request
In August 2026 Cisco disclosed CVE-2026-20349, an 8.6 CVSS flaw in the SSL VPN of its ASA and FTD firewalls: one unauthenticated HTTP request forces the device to reload and drops VPN access for every remote worker. With no workaround available, patching is the only fix — and the flaw is already being exploited in the wild.