// Darksteel Insights · 2026-08-12
Patch Now: Cisco Firewall Vulnerability Being Actively Exploited
A vulnerability in Cisco ASA and FTD firewalls is being actively exploited. SMBs must patch now to avoid network compromise.
- A vulnerability in Cisco ASA and FTD firewalls is being actively exploited.
- SMBs using these firewalls should apply patches immediately.
- Check your firewall version and contact your IT provider if unsure.
- If you suspect exploitation, isolate the device and seek expert help.
What is CVE-2026-20349 and why should I care?
CVE-2026-20349 is a heap inspection vulnerability in Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). This means an attacker can send specially crafted network traffic to the firewall that could cause it to behave unpredictably or allow unauthorized access to the network it’s meant to protect.
Firewalls are a critical part of your network’s defense. If compromised, attackers can bypass security controls and access internal systems and data. This vulnerability is being actively exploited, meaning it’s not just a theoretical risk—real attacks are already happening.
For small and mid-sized businesses, this is a serious concern. Many SMBs rely on these firewalls as their main security tool. A successful exploit could lead to unauthorized access, data exposure, or other serious incidents.
Does this affect my SMB?
If your business uses a Cisco Secure Firewall ASA or FTD, then yes, you are at risk. These firewalls are commonly used by SMBs to secure their network perimeters.
Cisco has released patches for this vulnerability. You must update to the latest versions to be protected. If you’re unsure whether your firewall is affected or how to apply the patch, contact your IT team or managed service provider for assistance.
If you’re not using Cisco firewalls, you are not directly affected by this specific issue. However, it’s a good reminder to ensure all your network devices are up to date and properly configured.
What should I do this week to protect my business?
First, identify whether you are using a Cisco ASA or FTD firewall. If you are, check the current software version and compare it to the patched versions listed in Cisco’s advisory. If you are running an older version, apply the patch immediately.
If you don’t have the in-house expertise to apply the patch or verify your firewall’s status, contact your IT provider or managed security service. They can help you assess your exposure and apply the necessary updates.
In the meantime, you can reduce risk by isolating the affected firewall from the internet or placing it behind another layer of security. However, this is only a temporary measure—patching is the only way to fully resolve the issue.
If you suspect your firewall has been compromised (e.g., unusual traffic, unexpected system behavior), isolate the device from your network immediately and contact a cybersecurity expert for further investigation.
How can I tell if my firewall has already been exploited?
Detecting exploitation of this vulnerability can be difficult because attackers often try to remain undetected. However, there are some signs to watch for. These include unexpected reboots of the firewall, unusual network traffic patterns (especially from the firewall to unknown external IP addresses), or performance issues that don’t have an obvious cause.
Review your firewall logs for any suspicious activity, such as unauthorized access attempts or unexpected configuration changes. If you see anything unusual, it’s a good idea to investigate further.
If you have a managed security service provider (MSSP) or use a security information and event management (SIEM) tool, they may be able to help detect signs of exploitation. If you don’t, consider reaching out to a cybersecurity firm for a forensic review of your firewall and network.
Not sure whether your environment is exposed? That is exactly what our Vulnerability Management service is built to surface. Talk to us.
Frequently asked questions
What is a heap inspection vulnerability?
Is this vulnerability being used in ransomware attacks?
Can I just disable the firewall until I can patch it?
What if I don't know which firewall I'm using?
How long do I have to patch this vulnerability?
What if I'm already being attacked through this vulnerability?
Source (public domain): CISA