Cisco ASA/FTD WebVPN crash/reload following inbound SSL VPN HTTP requests (CVE-2026-20349)
Detects Cisco network devices experiencing unexpected reloads, crashes, or watchdog resets that are correlated with prior incoming WebVPN, AnyConnect, or SSL VPN HTTP requests. The rule also identifies multiple device reloads occurring within a short 15-minute window, which may indicate a distributed or repeated exploitation attempt against the SSL VPN infrastructure.
Microsoft Sentinel (KQL)

