Number: AL26-018
Date: August 13, 2026
Audience
This Alert is intended for IT professionals and managers.
Purpose
An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Details
The Canadian Centre for Cyber Security (Cyber Centre) is aware of active exploitationFootnote 1 of a high-severity vulnerability affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) SoftwareFootnote 2. Cisco disclosed this vulnerability on August 11, 2026, and has confirmed active exploitation in the wild.
In response to the Cisco security advisory released on August 11, 2026, the Cyber Centre issued AV26-807Footnote 3 on August 12, 2026.
Tracked as CVE-2026-20349Footnote 4, this vulnerability is an Improper Clearing of Heap Memory Before Release ('Heap Inspection') (CWE-244)Footnote 5 vulnerability that may allow a remote attacker to cause a denial-of-service (DoS) condition. The vulnerability is caused by insufficient error checking when processing HTTP requests. An unauthenticated remote attacker could exploit the issue by sending a specially crafted HTTP request to an affected SSL VPN service. Successful exploitation could cause the firewall to reload unexpectedly, resulting in a denial of service (DoS) condition.
Cisco Secure Firewall ASA and Secure Firewall Threat Defense SSL VPN Services that are accessible from the internet, particularly those with the vulnerable SSL VPN-Related services enabled, are at risk of being impacted.
This vulnerability affects Cisco devices if they are running affected ASA or FTD software releases and have one or more of the following features enabled, which expose SSL listen sockets:
- IKEv2 Remote Access VPN with client services
- SSL VPN (WebVPN)
- Zero Trust Network Access (ZTNA) (FTD only)
Cisco has confirmed that Cisco Secure Firewall Management Center (FMC) Software is not affected by this vulnerability.
Suggested actions
The Cyber Centre recommends that organizations:
- Identify internet-accessible Cisco Secure Firewall ASA and FTD systems that provide Remote Access SSL VPN services.
- Determine whether WebVPN, IKEv2 Remote Access VPN (with client services), or Zero Trust Network Access features are enabled.
- Review firewall and VPN logs for evidence of unexpected reloads, service interruptions, or suspicious HTTP requests targeting SSL VPN services.
- Review whether SSL VPN, Remote Access VPN, or ZTNA services are enabled.
- Prioritize remediation of internet-facing systems.
Upgrade affected Cisco ASA instances to a fixed version:
| Affected product | Affected versions | Fixed versions |
|---|---|---|
| Cisco ASA | 9.16.x | 89.16.4.50 |
| Cisco ASA | 9.18.x | 89.18.4.50 |
| Cisco ASA | 9.20.x | 9.20.4.235 |
| Cisco ASA | 9.22.x | 9.22.3.191 |
| Cisco ASA | 9.23.x | 9.23.1.211 |
| Cisco ASA | 9.24.x | 9.24.1.221 |
| Cisco Secure Firewall FTD Software | 7.0.x | 7.0.9.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.2.x | 7.2.11.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.4.x | 7.4.7.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.6.x | 7.6.4.1 Hotfix |
| Cisco Secure Firewall FTD Software | 7.7.x | 7.7.11.1 Hotfix |
| Cisco Secure Firewall FTD Software | 10.0.x | 10.0.0.1 Hotfix |
The Cyber Centre recommends organizations:
- Review the Cisco advisory and evaluate exposure using the Cisco Software Checker.
- Ensure perimeter devices and VPN gateways are included in vulnerability management and patch management programs.
- Monitor network infrastructure for service disruptions and indicators of attempted exploitation.
- Consolidate, monitor, and defend Internet gateways.
- Patch operating systems, applications, and network infrastructure in a timely manner.
- Harden exposed services and minimize unnecessary internet-facing management interfaces.
- Follow Cisco’s remediation guidance and CISA KEV recommendations.
In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions with an emphasis on the following topicsFootnote 6Footnote 7.
- Consolidating, monitoring, and defending Internet gateways
- Patch operating systems and applications
- Harden operating systems and applications
- Isolate web-facing applications
Should activity matching the content of this alert be discovered, recipients are encouraged to report via My Cyber Portal or email contact@cyber.gc.ca.