Cisco ASA 및 FTD의 새로운 취약점이 악용된 사례가 발견되었다.
Cisco는 Secure Firewall Adaptive Security Appliance(ASA) 소프트웨어 및 Secure Firewall Threat Defense(FTD) 소프트웨어에 영향을 미치는 새로운 취약점에 대해 경고했다. 이 고위험 취약점(CVE-2026-20349)은 HTTP 요청 처리 시 오류 검사가 불충분하여 인증되지 않은 원격 공격자가 원격 서비스 거부(DDoS) 공격을 유발할 수 있는 문제이다. 현재 이 취약점은 실제 환경에서 악용되고 있는 것으로 보고되었다.
A new vulnerability in Cisco ASA and FTD has been exploited in the wild.
Cisco has warned of a new vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. The high-severity flaw, tracked as CVE-2026-20349, involves insufficient error checking when processing HTTP requests, allowing unauthenticated remote attackers to trigger a denial-of-service (DoS) attack. This vulnerability is currently reported to be exploited in the wild.