Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, kev, cisco, firewall, asa, ftd, unauthenticated, exploited-in-the-wild] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, finance, transport] ยท au_impact: true

CVE-2026-20349 โ€” Cisco Secure Firewall ASA/FTD Heap Inspection

CVE-2026-20349 is an unauthenticated heap-inspection vulnerability in Cisco Secure Firewall ASA/FTD allowing remote compromise. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-11 under BOD 26-04.

Vulnerability Details

Attribute Detail
CVE CVE-2026-20349
Type Unauthenticated heap-inspection vulnerability allowing remote compromise
Product Cisco Secure Firewall ASA/FTD
Access Unauthenticated
KEV status Added to KEV 2026-08-11 (BOD 26-04)
Exploitation status Actively exploited (KEV addition)

Context

CISA added the vulnerability to its KEV Catalogue on 2026-08-11 alongside CVE-2026-68820 (Windows afd.sys) and CVE-2026-72898 (Metabase). Cisco ASA/FTD firewalls are widely deployed at internet edge and remote-access boundaries; the digest notes the KEV-added Windows/Cisco bugs are the control class the ACSC Essential Eight patching discipline targets.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-12