Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Threats and Vulnerabilities

Your Firewall Is a Target, Not Just a Control

A new addition to the CISA Known Exploited Vulnerabilities Catalog puts the spotlight directly on firewalls from major vendors. Attackers are not waiting for theoretical gaps; they are finding and using real flaws in boundary protection. If your business relies on a firewall, keeping the device patched is the only way the boundary can actually protect you.

What recent firewall vulnerabilities should you know about?

The CISA Known Exploited Vulnerabilities Catalog as of August 14, 2026, lists 1,665 entries, with 181 added since January 1, 2026. Among these, several critical firewall vulnerabilities have been added in just the last few months.

For example, on August 11, 2026, CISA added CVE-2026-20349, a heap inspection vulnerability affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). While it is not yet confirmed whether this vulnerability has been used in ransomware campaigns, its inclusion in the catalog signals that it is known to be exploited.

Earlier this year, two other major firewall vendors had vulnerabilities added to the catalog, both flagged as having known ransomware campaign use:

  • CVE-2026-50751, an improper authentication vulnerability in Check Point Security Gateway, added June 8, 2026
  • CVE-2026-0257, an authentication bypass vulnerability in Palo Alto Networks PAN-OS, added May 29, 2026

These entries confirm that attackers are more than looking for weaknesses in your internal systems. They are targeting the very devices you rely on to keep threats out.

Are firewall vulnerabilities really being used in ransomware attacks?

Yes, according to the CISA Known Exploited Vulnerabilities Catalog, both the Check Point Security Gateway and Palo Alto Networks PAN-OS vulnerabilities listed above are specifically labeled as having known ransomware campaign use. This means attackers are exploiting these firewall vulnerabilities as entry points for ransomware.

In total, 349 entries in the CISA catalog are flagged for known ransomware campaign use. The catalog also includes other firewall and boundary device vulnerabilities, such as those affecting Cisco Secure Firewall Management Center (FMC) and SonicWall SMA1000 Appliances, which have also been used in ransomware campaigns.

What does this mean for your compliance obligations?

If you are working toward compliance with frameworks like CMMC or NIST SP 800-171, you are required to protect your network boundaries. For example, SC.L2 in CMMC (Level 2, based on NIST 800-171) assumes that boundary protection is maintained and up to date. In plain terms, this means your firewall must be patched against known vulnerabilities.

The CISA catalog is the authoritative list of vulnerabilities that must be addressed. If your firewall or security gateway appears in the catalog, you must take action. Simply having a firewall is not enough. If it is not patched, it can become the first point of compromise.

How do you know if your firewall is affected?

Check the CISA Known Exploited Vulnerabilities Catalog for your firewall product and version. The latest entries affecting firewalls are:

  • Cisco Secure Firewall ASA and FTD (CVE-2026-20349)
  • Check Point Security Gateway (CVE-2026-50751)
  • Palo Alto Networks PAN-OS (CVE-2026-0257)

If you use any of these products, you should check with your IT team or managed service provider to confirm the patch status and whether you are running a vulnerable version.

What should you do on Monday?

If you are responsible for IT or compliance in your business, take these steps:

  • Review the CISA Known Exploited Vulnerabilities Catalog for any entries related to your firewall or other boundary devices.
  • Confirm with your IT provider or internal team that all relevant patches have been applied.
  • Document your patching process and keep records of updates for compliance purposes.
  • Remember that compliance frameworks expect you to respond promptly to new vulnerabilities, especially those in the CISA catalog.

If you do not have a process in place to review and apply patches to your firewall, this is a critical gap. Attackers are targeting these devices precisely because they are often overlooked after initial setup.

Common questions

What is the CISA Known Exploited Vulnerabilities Catalog? The catalog is maintained by CISA and lists vulnerabilities that are known to be exploited in the wild. It is used by government and private organizations as a reference for required patching.

Does having a firewall mean I am compliant with CMMC or NIST 800-171? No. Compliance requires that the firewall is properly configured and patched. Boundary protection controls assume the device itself is not vulnerable.

How quickly do I need to patch vulnerabilities listed in the CISA catalog? You should address these vulnerabilities as soon as possible. The catalog is used by regulators and assessors as the standard for required action.

How Should You Harden Your Firewall

If you need to confirm your CMMC or NIST 800-171 readiness, consider an in kind CMMC Gap Assessment Grant from the Cyber Grants Alliance. This grant is delivered as services and covers all 110 controls for qualifying defense contractors. Learn more at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/. Taking action to address firewall vulnerability is more than best practice but a compliance requirement.

More on Threats

Threats · 4 min When Your IT Provider Is the Attack Path

Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.