Act
active
Cisco ASA and FTD Remote DoS Flaw Exploited in the Wild (CVE-2026-20349)
- Engineer — Act: CISA KEV listed, actively exploited in the wild, and a public PoC exists — patch Cisco ASA and FTD software immediately per Cisco’s advisory for CVE-2026-20349; perimeter firewall availability is at direct risk from unauthenticated remote attackers.
- SOC/IR — Act: Active exploitation of an edge security appliance warrants an assume-breach sweep — hunt for anomalous or malformed HTTP requests targeting ASA/FTD management interfaces and investigate any unexplained firewall availability incidents since this KEV listing date.
- Leader — Plan: A CISA KEV-confirmed flaw in widely deployed perimeter firewalls is a priority patching event — confirm your engineering team has this on the sprint and assess whether any availability SLAs tied to ASA/FTD deployments are at risk; DoS scope limits board-level urgency but warrants direct follow-up with the team.
- Signals: CVE-2026-20349 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.