type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, kev, cisco, firewall, asa, ftd, unauthenticated, exploited-in-the-wild] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, finance, transport] ยท au_impact: true
CVE-2026-20349 โ Cisco Secure Firewall ASA/FTD Heap Inspection
CVE-2026-20349 is an unauthenticated heap-inspection vulnerability in Cisco Secure Firewall ASA/FTD allowing remote compromise. CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-11 under BOD 26-04.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-20349 |
| Type | Unauthenticated heap-inspection vulnerability allowing remote compromise |
| Product | Cisco Secure Firewall ASA/FTD |
| Access | Unauthenticated |
| KEV status | Added to KEV 2026-08-11 (BOD 26-04) |
| Exploitation status | Actively exploited (KEV addition) |
Context
CISA added the vulnerability to its KEV Catalogue on 2026-08-11 alongside CVE-2026-68820 (Windows afd.sys) and CVE-2026-72898 (Metabase). Cisco ASA/FTD firewalls are widely deployed at internet edge and remote-access boundaries; the digest notes the KEV-added Windows/Cisco bugs are the control class the ACSC Essential Eight patching discipline targets.
Related Pages
- Cisa Adds Three Known Exploited Vulnerabilities To Catalog โ CISA KEV addition incident
Sources: raw/digests/Cyber-Digest-2026-08-12