CISA adds Cisco Secure Firewall vulnerability to the KEV Catalog
CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.
- Official source
- Cybersecurity and Infrastructure Security Agency ↗
- Jurisdiction
- United States
- Publication date
- August 11, 2026
- Legacy Core review
- August 17, 2026 · Christopher Green
- Source checked
- August 17, 2026
- Affected sectors
- Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
- Deadline date
- August 14, 2026
Summary
CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.
Why it matters
Some small offices reach the internet or remote VPN through a Cisco ASA or FTD appliance that an MSP selected and manages. The recorded impact is a denial of service, meaning an outage, not data theft. Catalog inclusion does not mean a particular firm runs this equipment.
Recommended action
Ask your IT owner or managed service provider which firewall your office uses and whether this Cisco update applies. Keep the response with your security-maintenance records.