Our takeCanadian Cyber Centre AL26-018 flags active exploitation of CVE-2026-20349 in Cisco ASA and Secure Firewall Threat Defense remote access SSL VPN. Patch now if you run these yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Apply the Cisco patch for CVE-2026-20349 immediately if you run ASA or Secure Firewall Threat Defense Remote Access SSL VPN. Monitor for exploitation per the CCCS advisory.
What this means for you — Lean IT orgs:If you use Cisco ASA or Secure Firewall for remote access VPN, update it now using the vendor instructions. Most small teams without these devices can ignore this.
What this means for you — MSP:Audit client environments for ASA and Secure Firewall Threat Defense Remote Access SSL VPN; deploy the CVE-2026-20349 patch where present and verify remote access configs.
What this means for you — Researcher:CCCS AL26-018 confirms active exploitation of CVE-2026-20349 in Cisco ASA and Secure Firewall Threat Defense Remote Access SSL VPN. Patch deployment priority is now elevated.