Cisco CVE-2026-20349: one unauthenticated HTTP request crashes ASA and FTD firewalls, actively exploited, CISA deadline today, no workaround      GeoServer zero-day: unauthenticated SQL injection in jsonArrayContains reaches RCE, no CVE, no patch, public PoC on GitHub, active probing within hours of disclosure      Adobe ColdFusion CVE-2026-48362: CVSS 10.0 unauthenticated OS command injection executes as SYSTEM, Priority 1, patch available, no exploitation confirmed yet      Cisco CVE-2026-20349: one unauthenticated HTTP request crashes ASA and FTD firewalls, actively exploited, CISA deadline today, no workaround      GeoServer zero-day: unauthenticated SQL injection in jsonArrayContains reaches RCE, no CVE, no patch, public PoC on GitHub, active probing within hours of disclosure      Adobe ColdFusion CVE-2026-48362: CVSS 10.0 unauthenticated OS command injection executes as SYSTEM, Priority 1, patch available, no exploitation confirmed yet     
CyberSipTM
Intelligence without the noise
Issue No. 108
August 14, 2026
3 items · past 24h
<5 min read
Today's picture

Cisco confirmed active exploitation of CVE-2026-20349, a flaw in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD that lets an unauthenticated attacker crash the firewall by sending one crafted HTTP request, with CISA setting today as the federal deadline and no workaround available for any affected configuration. A GeoServer zero-day in the jsonArrayContains filter expression has no CVE, no patch, and no vendor timeline for a fix, but has a public proof-of-concept exploit on GitHub and confirmed active probing within hours of its disclosure on August 12, with the attack path reaching remote code execution when the GeoServer backend runs on a Microsoft SQL Server database with elevated permissions. Adobe released patches for CVE-2026-48362, a CVSS 10.0 unauthenticated OS command injection in ColdFusion that executes arbitrary commands as the ColdFusion service account, alongside a CVSS 9.9 eval injection and a CVSS 9.6 authorization bypass, all with no exploitation confirmed in the wild but with Adobe's highest urgency rating applied.

Today's intelligence
3 items
01 HighCisco ASA / FTDCISA KEV
Cisco ASA and FTD firewalls are being crashed by unauthenticated attackers using one HTTP request, with the CISA deadline set for today
CVE-2026-20349 is a denial-of-service flaw in the Remote Access SSL VPN service. No credentials, no interaction, one crafted HTTP request to an internet-facing VPN endpoint, and the firewall reloads. For organizations that depend on Cisco ASA or FTD for remote access, the outage is immediate. The deadline was today. No workaround exists.
CVECVE-2026-20349
CVSS 8.6
KEV addedAugust 11, 2026
Fed deadlineAugust 14, 2026
(today)
AffectsASA and FTD with
SSL VPN, IKEv2
RA VPN, or ZTNA
WorkaroundNone
Cisco published its advisory for CVE-2026-20349 on August 11, 2026, after its Product Security Incident Response Team confirmed active exploitation in the wild during August. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 11 and set a federal remediation deadline of August 14, today. The flaw is in the Remote Access SSL VPN service shared by Cisco Secure Firewall Adaptive Security Appliance software and Cisco Secure Firewall Threat Defense software. Insufficient error checking when the service processes HTTP requests allows an unauthenticated remote attacker to send a specially crafted HTTP request that causes the affected device to reload unexpectedly, resulting in a denial-of-service condition that drops all active VPN sessions and any other services dependent on the device. No credentials are required. No user interaction is required. The attack is remote and the affected service is typically internet-facing by design. Three configurations expose a device to this vulnerability: SSL VPN enabled on any interface, IKEv2 Remote Access VPN with client services enabled, and Zero Trust Network Access enabled on FTD. MFA protects VPN account credentials but does not prevent unauthenticated HTTP traffic from reaching the SSL VPN service before any authentication step occurs. Cisco has released hotfixes covering ASA 9.16 through 9.24 and FTD 7.0 through 10.0. Cisco does not publish indicators of compromise for this vulnerability, meaning there is no log-based hunt available to confirm whether a specific device was targeted before patching. The impact is disruption rather than data exfiltration or code execution: a successful attack forces a firewall reload, which terminates all sessions. Repeated attacks can create sustained outages.
Cisco ASA and FTD are among the most broadly deployed enterprise firewall platforms. The Remote Access SSL VPN service is the entry point through which remote workers, contractors, and administrators connect to internal networks. An attacker who can crash the firewall on demand can disrupt remote access for an organization during a critical business period, force a controlled maintenance window that creates a secondary access opportunity, or use repeated crashes to degrade the security posture of the perimeter while other activity proceeds. The flaw does not exfiltrate credentials or give the attacker network access, but it gives any external party with knowledge of the CVE a reliable tool to disrupt the perimeter of any unpatched Cisco ASA or FTD deployment at will.
This is the fourth Cisco firewall-related advisory to appear on CISA KEV in 2026. Cisco FMC CVE-2026-20316 in Issue 99 was a hardcoded static credential. Cisco SD-WAN and IOS XE critical flaws appeared in the August 6 search results. CVE-2026-20349 now follows. The pattern of sustained attacker interest in Cisco network security infrastructure is consistent with what this brief has documented for firewall management planes across Check Point, VMware, and N-able throughout the year. Cisco's advisory also notes that independent security researcher Valerio Brussani reported the vulnerability, meaning it was discovered externally rather than only through Cisco's internal testing. The combination of external discovery, active exploitation, and confirmed in-the-wild attacks before the advisory published suggests the vulnerability was known to attackers before Cisco's advisory date.
  • Apply the Cisco hotfix for CVE-2026-20349 to all ASA and FTD devices running SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access. The hotfix advisory is cisco-sa-asaftd-vpn-dos-dzv4mQFF. Match the hotfix to the specific ASA or FTD software train in use. The CISA deadline was today, and active exploitation is confirmed.
  • If immediate patching is not possible, restrict unauthenticated HTTP access to the SSL VPN service interface from known IP ranges at an upstream firewall or load balancer. This does not eliminate the vulnerability but reduces the population of attackers who can reach the affected endpoint until the hotfix can be applied.
  • Monitor firewall availability logs for unexpected reloads on ASA and FTD devices since August 11. Cisco does not publish specific indicators of compromise, but unexpected reloads on internet-facing firewall appliances since that date should be investigated as potential exploitation attempts given the confirmed active exploitation of CVE-2026-20349.
One HTTP request. No credentials. The firewall crashes and every VPN session drops. Actively exploited. No workaround. The federal deadline was today. Apply the hotfix and check the reload logs from August 11 onward.
02 CriticalGeoServerZero-Day
GeoServer has an unpatched SQL injection zero-day with a public exploit that reaches remote code execution under common database configurations
No CVE. No patch. No vendor timeline. A bug bounty hunter posted it to X on August 12 and exploitation probing began within hours. The flaw is in jsonArrayContains, a filter used with PostGIS and Oracle JDBC data stores. When the backend is Microsoft SQL Server running as a system administrator, the SQL injection becomes full operating system command execution. A working PoC is on GitHub.
CVENot assigned
PatchNot available
DisclosedAugust 12, 2026
@q1uf3ng on X
ExploitationActive probing
within hours
PoCPublic on GitHub
mhtsec/GeoServer
On August 12, 2026, a security researcher posting as @q1uf3ng on X disclosed an unpatched SQL injection vulnerability in GeoServer's jsonArrayContains function. GeoServer is an open-source Java application for sharing, processing, and editing geospatial data, widely used by government agencies, defense contractors, environmental agencies, research institutions, and engineering organizations to serve geographic data through OGC-compliant web services. The jsonArrayContains function is a filter expression used to query JSON array fields in PostGIS and Oracle JDBC data stores. It accepts user-supplied arguments that are not properly sanitized before being encoded into database queries. An unauthenticated attacker who can send requests to an exposed GeoServer Web Feature Service endpoint can inject arbitrary SQL through those arguments. The SQL injection's impact depends on the database configuration. When GeoServer connects to a PostgreSQL database with standard permissions, the injection gives read access to accessible tables. When GeoServer connects to a Microsoft SQL Server instance running as a system administrator account, the SQL injection enables the xp_cmdshell extended stored procedure, converting the injection into operating system command execution. A separate researcher confirmed the flaw was reproducible in a non-default configuration on X the same day. WatchTowr observed hundreds of exploitation probing attempts from a small number of source IP addresses within hours of the disclosure. A public proof-of-concept exploit, including a Python script targeting PostgreSQL backends, has been available on GitHub since August 12. No CVE has been assigned. GeoServer has not published a security advisory or patch timeline as of August 14. GeoServer has multiple prior CVEs on CISA KEV, including CVE-2024-36401 from 2024, which was exploited to deploy Mirai botnet malware, SideWalk backdoors, and cryptocurrency miners.
GeoServer is used across government, defense, environmental, and infrastructure sectors precisely because those sectors work with geospatial data. Government mapping portals, defense infrastructure visualization systems, environmental monitoring platforms, and utility network management applications frequently run GeoServer as the data-serving layer behind public or semi-public web interfaces. The no-CVE, no-patch status creates an operational gap similar to the Metabase situation from Issue 105: organizations whose vulnerability tracking depends on CVE identifiers will not surface this exposure until a CVE is assigned. WatchTowr's Jake Knott stated publicly that this situation is unlikely to remain at the probing stage for long given GeoServer's track record of being targeted and exploited at scale. The Microsoft SQL Server attack path is the higher-severity scenario: organizations that run GeoServer connected to a SQL Server instance with elevated database permissions should treat the SQL injection as a potential OS command execution path until a patch is available.
The GeoServer prior exploitation history is directly relevant to how urgently this should be treated. CVE-2024-36401 was added to CISA KEV in 2024 and exploited broadly within days of public disclosure. The actors who exploited CVE-2024-36401 included Mirai botnet operators, nation-state actors deploying backdoors, and financially motivated actors deploying cryptocurrency miners. GeoServer's attack surface is primarily government and research infrastructure, which means the actors who have historically targeted it include sophisticated state-sponsored groups seeking geospatial intelligence data alongside opportunistic automated scanners. The public PoC on GitHub reduces the skill barrier for exploitation significantly. An attacker who can run a Python script against an exposed GeoServer endpoint can confirm whether the target is vulnerable with no specialized knowledge of the underlying flaw.
  • Identify all GeoServer instances in your environment and determine whether any are internet-facing or accessible from untrusted networks. Restrict public access to GeoServer Web Feature Service endpoints at the network perimeter while no patch is available. A GeoServer instance that cannot be reached by unauthenticated external HTTP requests is not exploitable through this zero-day regardless of the underlying database configuration.
  • For GeoServer instances connected to Microsoft SQL Server backends, review the database account permissions granted to the GeoServer application. The SQL injection to OS command execution path requires the database account to have system administrator permissions. Restricting GeoServer's database account to the minimum permissions needed for its data-serving function, specifically excluding the ability to enable or call xp_cmdshell, limits the worst-case impact of the SQL injection even without a patch.
  • Monitor your GeoServer access logs for unusual query patterns to the jsonArrayContains filter function since August 12, particularly requests containing single-quote characters, SQL syntax keywords, or encoded SQL payloads in JSON array filter expressions. WatchTowr's observed probing attempts came from a small number of source IPs, meaning firewall logs showing repeated requests from unfamiliar addresses to WFS endpoints are meaningful indicators.
No CVE, no patch, public PoC, active probing within hours of disclosure. If GeoServer connects to a SQL Server database running as a system administrator, the SQL injection becomes OS command execution. Restrict network access to GeoServer endpoints now. Check whether the database account has the permissions that make this the worst-case scenario.
03 CriticalAdobe ColdFusionPriority 1
Adobe patched a CVSS 10.0 unauthenticated OS command injection in ColdFusion that runs arbitrary commands as the service account
CVE-2026-48362 requires no authentication and no user interaction. An attacker sends one crafted request and executes operating system commands as NT AUTHORITY\SYSTEM on Windows. ColdFusion CVE-2026-48282, from last month's advisory, was actively exploited within days of disclosure. Adobe assigned Priority 1, meaning patch within 72 hours.
Lead CVECVE-2026-48362
CVSS 10.0
Also patchedCVE-2026-48273
CVSS 9.9 (eval inj)
CVE-2026-71384
CVSS 9.6 (auth bypass)
Fixed inCF 2025: 2025.0.12
CF 2023: 2023.0.23
PriorityAdobe Priority 1
(patch within 72h)
ExploitationNot confirmed
in wild yet
Adobe published security bulletin APSB26-83 on August 12, 2026, addressing multiple critical vulnerabilities in Adobe ColdFusion 2025 and ColdFusion 2023. The most severe flaw is CVE-2026-48362, an OS command injection vulnerability rated CVSS 10.0. The vulnerability arises from improper neutralization of special elements used in operating system commands, allowing an unauthenticated remote attacker to execute arbitrary commands in the context of the ColdFusion service account. On Windows, that account is typically NT AUTHORITY\SYSTEM, the highest level of access on the operating system. No authentication and no user interaction are required. The same bulletin addresses CVE-2026-48273, a CVSS 9.9 eval injection vulnerability that can lead to arbitrary code execution by an attacker with low-level privileges, and CVE-2026-71384, a CVSS 9.6 incorrect authorization vulnerability that can produce application denial-of-service. Adobe also addressed CVE-2026-71362, a CVSS 9.1 incorrect authorization flaw in Adobe Commerce that can lead to privilege escalation, and CVE-2026-48381, a CVSS 9.0 SQL injection in Adobe Campaign Classic that can lead to code execution. Fixed ColdFusion versions are 2025.0.12 and 2023.0.23. Adobe assigned its Priority 1 rating to the ColdFusion and Campaign Classic updates, which Adobe describes as a recommendation to install within 72 hours due to elevated risk of being targeted by malicious attacks. Adobe stated it is not aware of any exploits targeting these vulnerabilities in the wild as of the publication date.
Adobe ColdFusion has an active exploitation pattern that makes the absence of confirmed in-the-wild exploitation at publication time a limited reassurance. CVE-2026-48282, a separate ColdFusion path traversal flaw patched in June, was being exploited within days of its disclosure. KEVIntel honeypots detected active exploitation of that flaw within two hours of the technical write-up. ColdFusion is used in government agencies, healthcare systems, financial institutions, and enterprise web applications. An OS command injection on a ColdFusion server typically gives an attacker the ability to install a webshell, exfiltrate data, pivot to connected databases, and move laterally through the host's network. The CVSS 10.0 rating and Priority 1 designation reflect the maximum practical impact of the flaw: unauthenticated, no user interaction, arbitrary OS command execution as SYSTEM.
The ColdFusion advisory is the third major Adobe security release this month, alongside the emergency SAP CVE-2026-58231 note from Issue 107 and the vCenter campaign from Issue 107. Organizations managing enterprise web application infrastructure are navigating simultaneous critical patches from Adobe, SAP, Microsoft, Cisco, and VMware in the same week. Adobe's 72-hour Priority 1 guidance for ColdFusion is the correct prioritization signal. The broader enterprise patching queue this week, including today's Cisco ASA deadline, last week's Metabase zero-day, and the ongoing vCenter campaign, reflects the sustained high-volume patching environment this brief documented across all of July and August. Triage by exploitation status and internet exposure remains the only workable framework: ColdFusion CVE-2026-48362 is not yet exploited but has a recent predecessor that was. The Cisco CVE is already being exploited. The GeoServer zero-day has no patch at all. Those three categories require different response timelines even when they arrive on the same day.
  • Update ColdFusion 2025 deployments to version 2025.0.12 and ColdFusion 2023 deployments to version 2023.0.23 within 72 hours per Adobe's Priority 1 guidance. Internet-facing ColdFusion servers are the highest-priority update targets given the unauthenticated attack surface of CVE-2026-48362.
  • Also apply the Campaign Classic update for CVE-2026-48381 and the Commerce update for CVE-2026-71362 if those products are in use. Adobe-hosted instances of Campaign Classic have already been remediated and require no action. On-premise deployments and hybrid on-premise components require manual update.
No authentication. No interaction. OS commands execute as SYSTEM. Not exploited in the wild yet, but last month's ColdFusion advisory was actively attacked within hours of the technical write-up. Adobe says patch within 72 hours. The clock started August 12.
Cross-source standouts
01
Three stories, three different patch states: exploited with a patch, exploited without a patch, and patched without exploitation — and why they require different response timelines
Today's three stories represent the three distinct operational states a security team must triage simultaneously. Cisco CVE-2026-20349 is exploited in the wild and has a patch. The response is to patch immediately, because active exploitation plus available fix means every hour of delay is an hour of confirmed exposure. The GeoServer zero-day is being actively probed in the wild with no patch available. The response is to reduce attack surface while waiting, because there is nothing else to do: restrict network access, review database permissions, monitor logs, and wait for a patch. Adobe ColdFusion CVE-2026-48362 has a patch but no confirmed exploitation. The response is to patch within the vendor's stated 72-hour window, because ColdFusion's exploitation history suggests that window will not remain wide for long. These three states require different urgencies and different remediation sequences, but all three require action today. The error is treating them identically, either by applying uniform urgency to all three regardless of exploitation status, or by deprioritizing the no-exploitation story because it lacks the immediate alarm of confirmed in-the-wild attacks. Adobe's Priority 1 designation exists precisely to prevent the latter error: the vendor is telling you this is the category of flaw that becomes the Cisco story if left unpatched.
02
GeoServer, Metabase, and the no-CVE operational gap: when vulnerability tracking based on CVE identifiers misses active zero-days
Issue 105 covered the Metabase zero-day tracked as GHSA-vwf4-m7j8-wcjf, which had a CVSS 10.0 rating and active exploitation confirmed from August 3. It had no CVE identifier at the time of disclosure. The GeoServer zero-day disclosed on August 12 is in the same position: active exploitation probing, a public proof-of-concept, and no CVE assigned. The practical consequence in both cases is the same. Organizations whose vulnerability management relies on NVD feeds, CVE-tagged SIEM rules, or patch management systems that filter by CVE status will not surface either vulnerability until a CVE is assigned. A vulnerability scanner that checks installed software versions against CVE-tagged advisories will show a clean result for GeoServer deployments running the current version because there is no CVE to match against. The gap between when a vulnerability is publicly known and actively probed and when it enters CVE-based tracking systems is not a brief administrative delay. It can span days to weeks, during which organizations relying on CVE-based workflows have no automated signal that their exposed GeoServer instances are being probed. The operational requirement is to monitor sources that track active exploitation and researcher disclosures, not only CVE database feeds, specifically because this gap recurs with meaningful frequency in the current threat environment.
Still watching
Days 2–5
LiteLLM CVE-2026-33634 credential exposure (Issue 107 · 153GB archive surfaced August 13) — check Hudson Rock Cavalier and CloudSEK lookup tools. Rotate all cloud keys, SSH keys, Kubernetes tokens, repository tokens, and AI provider keys from any pipeline that ran LiteLLM 1.82.7 or 1.82.8. Audit any packages published in the March 24 to 26 window for tampering.
Day 2
VMware vCenter CVE-2026-59310 (Issue 107 · APT campaign, 361 victims, 47 countries) — apply VMSA-2026-0006.1. Hunt for unexpected cron jobs, reverse_ssh binaries, and outbound SSH from vCenter since August 3. Use QUIRSO YARA rules. Any vCenter accessible since August 3 should be treated as potentially compromised until cleared.
Day 2
Metabase GHSA-vwf4-m7j8-wcjf (Issue 105 · CVSS 10.0 zero-day, exploited August 3) — patch self-hosted instances. Rotate database credentials for every connected source. Add GHSA-vwf4-m7j8-wcjf to tracking tools manually. CVE-based scanners will not surface this flaw.
Day 5
Atlassian Rovo content-borne prompt injection (Issue 104 · PromptArmor, reported May 2026) — URL parameter path patched July 8. Content-borne path status unconfirmed as of August 14. Scope Rovo access tightly and audit Rovo Connector connections to external platforms until Atlassian confirms both paths are closed.
Day 7+