Legacy Core
Official Guidance

CISA adds Cisco Secure Firewall vulnerability to the KEV Catalog

CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.

Official source
Cybersecurity and Infrastructure Security Agency
Jurisdiction
United States
Publication date
August 11, 2026
Legacy Core review
August 17, 2026 · Christopher Green
Source checked
August 17, 2026
Affected sectors
Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
Deadline date
August 14, 2026

Summary

CISA added CVE-2026-20349, a Cisco Secure Firewall ASA and FTD vulnerability that can force an unexpected device reload, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 14, 2026 applies to federal agencies, not to private businesses.

Why it matters

Some small offices reach the internet or remote VPN through a Cisco ASA or FTD appliance that an MSP selected and manages. The recorded impact is a denial of service, meaning an outage, not data theft. Catalog inclusion does not mean a particular firm runs this equipment.

Recommended action

Ask your IT owner or managed service provider which firewall your office uses and whether this Cisco update applies. Keep the response with your security-maintenance records.

CISA adds Cisco Secure Firewall vulnerability to the KEV Catalog — Legacy Core Intelligence | Legacy Core