Official sources used

Cisco security advisories, Fortinet PSIRT, Fortinet upgrade tool, Zyxel security advisories, Zyxel download center

This roundup only references official vendor material. It is meant to shorten the path from “I heard about a firewall issue” to “what fixed version does the vendor actually say to run?”

Cisco Secure Firewall2026-08-11active exploitation response

Cisco Secure Firewall ASA/FTD Remote Access SSL VPN DoS update

Cisco says an unauthenticated remote attacker can send crafted HTTP requests to the Remote Access SSL VPN service and force an affected Secure Firewall ASA or FTD device to reload unexpectedly, and Cisco later disclosed active exploitation in August 2026.

Key fixed versionsASA 9.16.4.50, 9.18.4.50, 9.20.4.235, 9.22.3.191, 9.23.1.211, 9.24.1.221; FTD Hotfix GC-7.0.9.1-1, HM-7.2.11.1-2, HK-7.4.7.1-1, DD-7.6.4.1-2, and AN-7.7.11.1-2
Why it belongs hereThis is a high-value firewall operator record: remote unauthenticated impact, active exploitation, and exact fixed software across current ASA and FTD trains.
Fortinet2026-07-04authentication bypass

FG-IR-25-1052 LDAP authentication bypass in Agentless VPN and FSSO

Fortinet says an unauthenticated attacker may be able to bypass LDAP authentication for Agentless VPN or FSSO policies under a specific LDAP-server configuration, making this a cleaner current firewall-operations story than generic release churn.

Key fixed versionFortiOS 7.6.5+
Why it belongs hereIt is a fresh first-party FortiOS advisory with a named CVE, one exact fixed release, and a vendor-published workaround to disable unauthenticated LDAP bind.
Cisco Secure Firewall2026-04-23active exploitation response

Cisco Secure Firewall ASA/FTD persistence response after CISA ED 25-03 update

Cisco says affected Secure Firewall ASA and FTD hardware can retain a persistent implant even after the September 2025 fixes, so operators should check for compromise, reimage if needed, and move to the listed fixed releases and hotfixes.

Key fixed versionsASA 9.16.4.92, 9.18.4.135, 9.20.4.30, 9.22.3.5, 9.23.1.195, 9.24.1.155; FTD 7.0.9 + FZ-7.0.9.1-3, 7.2.11 + HI-7.2.11.1-1, 7.4.7, 7.6.4 + CC-7.6.4.1-1, and 7.7.11 + AE-7.7.11.1-4
Why it belongs hereThis is unusually strong Cisco operator guidance: affected platforms, compromise checks, reimage guidance, and fixed software tables are all on the official page.
Zyxel2026-08-04

Zyxel fixes CVE-2026-14818 in ZLD firewalls

Zyxel says a path traversal issue in the configuration-file execution CLI command of certain ZLD firewalls could let an authenticated administrator execute a crafted malicious configuration file.

Fixed versionZLD V5.43 across ATP, USG FLEX, and USG FLEX 50(W) / USG20(W)-VPN
Why it mattersThis stays in the core firewall lane and gives a cleaner patch target than Zyxel's broader CPE or AP-heavy advisories.
Zyxel2025-04-22

Zyxel USG FLEX H privilege escalation security update

Zyxel published a clean firewall advisory for privilege escalation issues affecting USG FLEX H devices and explicitly called out the patched train.

Fixed versionuOS V1.32
Why it mattersThis broadens firewall coverage with a credible second manufacturer that still gives readers clear first-party patch targets.
Fortinet2025-01-15potentially exploited

FG-IR-24-015: SSL-VPN out-of-bounds write

Fortinet says this FortiOS and FortiProxy issue may allow remote unauthenticated code execution via crafted HTTP requests and notes potential exploitation in the wild.

Key fixed versionsFortiOS 7.4.3+, 7.2.7+, 7.0.14+, and 6.4.15+
Why it belongs hereIt combines remote reachability, serious impact, and a crisp vendor upgrade target.
Fortinet2025-03-31exploited in the wild

FG-IR-24-535: Authentication bypass / super-admin risk

Fortinet says crafted requests may allow a remote attacker to gain super-admin privileges and explicitly notes that the issue is being exploited in the wild.

Key fixed versionsFortiOS 7.0.17+, FortiProxy 7.2.13+, and FortiProxy 7.0.20+
Why it belongs hereAny firewall issue that combines authentication bypass, privilege takeover, and active exploitation deserves a durable static reference page.