Cisco warns of ASA and FTD VPN flaw; Ncerio audits show persistent configuration gaps
BleepingComputer reports active exploitation of a denial-of-service flaw in Cisco Secure Firewall software. Our continuous audit reveals 1,713 open issues across 54 audited targets.
11 August 2026
Cisco has issued a warning regarding a high-severity vulnerability in its Secure Firewall ASA and Threat Defense (FTD) software, which is currently being actively exploited to crash devices remotely. According to BleepingComputer, the flaw allows attackers to trigger a denial-of-service condition without requiring authentication, effectively taking the affected network security appliances offline.
The incident highlights the fragility of perimeter defense systems when critical firmware or software components contain unpatched logic errors. While the specific technical details of the exploit mechanism remain under active investigation by security researchers, the immediate impact is clear: the integrity and availability of Cisco firewall infrastructure are directly compromised by this single entry point. Network administrators relying on these devices for traffic filtering and threat prevention face a risk of sudden service disruption.
At Ncerio, we do not measure specific incidents as they break; we maintain a continuous baseline of configuration posture across our client estates. This ongoing measurement provides a factual snapshot of the environment independent of breaking news cycles. Our most recent audit of 54 Cisco targets identified 1,713 open configuration issues, distributed across four severity levels: 62 critical, 331 high, 803 medium, and 517 low.
The data reveals specific areas where the estate diverges from established hardening standards. The most prevalent gap relates to rule CIS-L2-BPDU-001, which mandates that BPDU Guard be enabled by default on PortFast or edge access ports. This misconfiguration was found across all 54 audited targets, leaving the network vulnerable to Spanning Tree Protocol manipulation and potential loop-induced outages.
A second widespread issue involves rule INV-EOL-001, which requires that devices do not run end-of-support operating systems. All 54 targets in this audit are running versions of Cisco software that have reached their end-of-life date. These systems no longer receive security updates from the vendor, meaning any new vulnerability discovered in the codebase will remain unpatched by official channels.
The third significant gap is found in rule CIS-IOS-SSH-001, which stipulates that SSH must be pinned to version 2. SSHv1 is cryptographically broken and susceptible to various attacks. This specific misconfiguration was present on 52 of the 54 audited targets, indicating that legacy management protocols are still widely active within the estate, providing an unnecessary attack vector for credential interception.
It is important to clarify what this data does not show. The 1,713 open findings represent configuration drift and policy violations against internal baselines and CIS benchmarks. They do not indicate that the audited estate is currently affected by the specific remote crash vulnerability reported by BleepingComputer. We cannot determine if the active exploit in the wild targets the specific software versions or configurations present in our audit data. The link between the news item and our measurement is purely topical: both concern the security posture of Cisco network infrastructure.
To address the most critical gaps identified in this audit, prioritize reviewing the 62 open critical findings immediately. Simultaneously, plan a migration path for the 54 devices running end-of-support operating systems to reduce long-term exposure to unpatched vulnerabilities.