Current status

Two operator-grade Cisco Secure Firewall records are now indexed

Cisco's advisory estate is still broad, but the site now has two public Secure Firewall records because the official sources clearly name affected software trains, fixed ASA and FTD targets, and the operator action Cisco wants customers to take.

Indexed nowCisco's August 2026 Remote Access SSL VPN DoS advisory and April 2026 persistence-response advisory both clear the bar with explicit fixed software guidance.
Still not in scopeGeneric Cisco advisories without crisp Secure Firewall version guidance, or filler pages that say Cisco is covered when it is not.
active exploitation response2026-08-11

Cisco Secure Firewall ASA/FTD Remote Access SSL VPN DoS update

Cisco says an unauthenticated remote attacker can send crafted HTTP requests to the Remote Access SSL VPN service and force an affected Secure Firewall ASA or FTD device to reload unexpectedly, and Cisco later disclosed active exploitation in August 2026.

AffectedASA 9.16, 9.18, 9.20, 9.22, 9.23, and 9.24 plus FTD 7.0, 7.2, 7.4, 7.6, and 7.7 when Remote Access SSL VPN is enabled.
Fixed version(s)ASA 9.16.4.50, 9.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221; FTD Hotfix GC-7.0.9.1-1, HM-7.2.11.1-2, HK-7.4.7.1-1, DD-7.6.4.1-2, and AN-7.7.11.1-2.
active exploitation response2026-04-23

Cisco Secure Firewall ASA/FTD persistence response after CISA ED 25-03 update

Cisco says affected Secure Firewall ASA and FTD hardware may retain a persistent implant even after upgrading to the September 2025 fixes, so operators should check for compromise, reimage if needed, and move to the listed fixed ASA and FTD releases and hotfixes.

AffectedFirepower 1000/2100/4100/9300 and Secure Firewall 1200/3100/4200 platforms.
Fixed version(s)ASA 9.16.4.92, 9.18.4.135, 9.20.4.30, 9.22.3.5, 9.23.1.195, 9.24.1.155; FTD 7.0.9 + FZ-7.0.9.1-3, 7.2.11 + HI-7.2.11.1-1, 7.4.7, 7.6.4 + CC-7.6.4.1-1, 7.7.11 + AE-7.7.11.1-4.
Editorial rule

What would make a Cisco record worth publishing here

  • An official Cisco advisory or release reference tied clearly to Secure Firewall, FTD, or FMC.
  • Affected trains named precisely enough that an operator can decide whether to care.
  • A fixed version or upgrade target stated explicitly by Cisco.
  • Enough operator value to beat the current Fortinet and Zyxel firewall lane instead of diluting it.