Critical Analysis: CVE-2026-20349 - Cisco Secure Firewall Adaptive Security Appliance (ASA) and ... — August 14, 2026
Published 14 Aug 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
AGMP Partners Initial Discovery and Context Alright, let's cut straight to it. We're looking at CVE-2026-20349, a critical heap inspection vulnerability disclosed today, August 14, 2026, impacting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). This isn't just another bug; this is a prime target for nation-state actors and sophisticated criminal enterprises given the pervasiveness of these devices at the network perimeter. The vulnerability stems from improper handling of specific IPv4 options within packets traversing the firewall, leading to a heap corruption scenario. It's classified with a CVSS v3.1 score of 9.8 (Critical), indicating an unauthenticated, remote exploit that can lead to arbitrary code execution. The discovery itself, as per Cisco's advisory, came through internal security research, which is a testament to their continu