Cisco ASA and FTD CISA KEV: Patch CVE-2026-20349
August 11, 2026
CISA added Cisco ASA and FTD CVE-2026-20349 to its Known Exploited Vulnerabilities catalog on August 11, 2026. Cisco rates the Remote Access SSL VPN issue High, reports active attacks, and says no workaround replaces a fixed software update. Affected devices can reload unexpectedly, so treat this as an emergency firewall and remote-access maintenance change.
Who should act
Review Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defense devices that provide Remote Access SSL VPN services. Cisco’s advisory identifies vulnerable software releases and the supported fixed releases. Cisco Secure Firewall Management Center is not affected by this specific issue, but it remains part of the normal maintenance and monitoring workflow for managed firewall environments.
Plan a controlled firewall update
- Identify every affected ASA and FTD device, its software release, its Remote Access SSL VPN role, and its high-availability or maintenance dependencies.
- Open an emergency change with an owner, remote-user communication, a defined maintenance window, and a recovery decision point.
- Use the documented Cisco compatibility and upgrade path for the installed release. Apply the vendor-fixed software rather than relying on a temporary workaround.
- For a high-availability pair or clustered design, follow the established rolling maintenance order and preserve the approved access path for administrators.
- After each device is updated, confirm appliance health, failover state where applicable, approved remote access, monitoring, and normal traffic flow before proceeding.
Protect availability while the change is scheduled
Do not treat a web-application control as a replacement for the Cisco software update. While the change is being arranged, review whether public firewall administration and remote-access exposure match your approved access policy. Use established network and identity controls to keep administration limited to approved staff without interrupting legitimate remote workers or customer operations.
Validate after patching
- Record the post-change software release and update time for each appliance.
- Validate the Remote Access SSL VPN service with authorized accounts and normal identity controls.
- Confirm high-availability health, routing, monitoring, alerting, and service availability.
- Review system events for unexpected reloads or configuration changes that need escalation.
- Send affected users a concise completion and follow-up status.
Keep Cisco security work separate and current
This is a product-specific ASA and FTD update. Teams operating Cisco management infrastructure should also keep their Cisco FMC CISA KEV checklist current, but do not merge unrelated changes into the firewall maintenance window.

