Security NEXTAugust 12, 2026🇯🇵Translated from Japanese

CVE-2026-20349: Cisco ASA and FTD Firewalls Face Remote DoS in SSL VPN, Already Exploited

Cisco Systems has published a security advisory detailing a denial-of-service vulnerability in its Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. The flaw, identified as CVE-2026-20349, affects the SSL VPN functionality used for remote access.

Attackers can exploit insufficient validation of HTTP requests to send a maliciously crafted packet that forces the device to reboot without requiring authentication. This results in a complete service denial for VPN users and any connected sessions. The same issue extends to FTD configurations running Zero Trust Network Access.

The vulnerability received a CVSS v3.1 base score of 8.6 and is rated High severity. Cisco confirmed that exploitation attempts were observed in the wild during August 2026, making this a confirmed zero-day case prior to the advisory release on 11 August 2026.

Hotfixes addressing the issue are now available for both ASA and FTD. Administrators are strongly advised to apply the updates immediately. Cisco Secure Firewall Management Center (FMC) is not impacted by this vulnerability.

Related articles

HabrVulnerabilities & Exploits

Agent, Scan or Beyond: Modern Methods for Comprehensive Infrastructure Vulnerability Scanning

The eighth installment in the Vulnerability Management for Beginners series explains why traditional scanning approaches no longer cover today's dynamic environments. It details three classic methods—Host Discovery, Pentest, and Audit—alongside agent-based scanning, cloud snapshot techniques, passive traffic analysis, container and SCA tools, and integrations with existing IT systems. The guide stresses that agents from Tenable and Qualys complement but do not replace network scanning, while Orca Security and Wiz pioneered disk snapshot analysis for short-lived cloud instances. It also covers container image scanning with Trivy and Grype before deployment, passive monitoring for OT environments, and the importance of combining multiple data sources to eliminate blind spots. Practical recommendations include scanning frequency by asset type and six post-scan steps for effective remediation.

Security NEXTVulnerabilities & Exploits

Adobe Releases Third Emergency Patch for Campaign Classic in Two Weeks, Fixing Critical RCE Vulnerabilities

Adobe has issued another urgent security update for Adobe Campaign Classic after discovering multiple critical vulnerabilities that affect the previous patches released on July 29 and August 3. The new advisory, published on August 11, 2026, addresses three CVEs rated Critical, including two remote code execution flaws with CVSSv3.1 base scores of 10.0. These authorization bypass issues allow unauthenticated attackers to execute arbitrary code remotely. The affected versions include 7.4.3 build 9398 and build 9399, which were themselves emergency fixes issued only days earlier. Adobe urges all customers to apply the latest update immediately due to the high risk of exploitation. This marks the third high-severity patch for the product within a two-week period.

Security NEXTVulnerabilities & Exploits

SonicWall Global Management System Hit by Critical RCE and Path Traversal Vulnerabilities

SonicWall has disclosed six vulnerabilities in its SonicWall Global Management System (GMS) management product, with the highest-severity issues rated Critical. The most severe flaw, CVE-2026-66147, resides in the Dispatcher Service and allows unauthenticated remote code execution through crafted requests that inject commands. A second critical issue, CVE-2026-66145, stems from improper handling of zip archive extraction and enables path traversal attacks that can read sensitive data or write arbitrary files without authentication. Both vulnerabilities received CVSSv3 base scores above 9.0. The flaws affect both the virtual appliance and Windows versions of GMS. SonicWall released an advisory on August 11 urging immediate application of the available updates.

Security NEXTVulnerabilities & Exploits

Adobe Issues Critical Security Updates for ColdFusion with Multiple High-Severity Vulnerabilities

Adobe has released security updates for Adobe ColdFusion to address 15 vulnerabilities disclosed in a security advisory on August 11, 2026. Among them, CVE-2026-48362 is an OS command injection flaw that allows arbitrary code execution and carries the maximum CVSSv3.1 base score of 10.0. Two additional issues, CVE-2026-48273 involving dynamic code evaluation and CVE-2026-71384 related to authorization bypass leading to denial of service, received scores of 9.9 and 9.6 respectively. Eight further vulnerabilities were rated Critical, prompting Adobe to urge immediate patching. The advisory highlights risks across multiple attack vectors and emphasizes rapid remediation to prevent potential exploitation.