CVE-2026-20054Medium· 5.8▾ SunlitMultiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper error …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to enter an infinite loop, causing a DoS condition.
snort >= 3.0.0-233, < 3.9.3.0cyber_vision = 3.0.0cyber_vision = 3.0.1cyber_vision = 3.0.2cyber_vision = 3.0.3cyber_vision = 3.0.4cyber_vision = 3.0.5cyber_vision = 3.0.6cyber_vision = 3.1.0cyber_vision = 3.1.1cyber_vision = 3.1.2cyber_vision = 3.2.0cyber_vision = 3.2.1cyber_vision = 3.2.2cyber_vision = 3.2.3cyber_vision = 3.2.4cyber_vision = 4.0.0cyber_vision = 4.0.1cyber_vision = 4.0.2cyber_vision = 4.0.3cyber_vision = 4.1.0cyber_vision = 4.1.1cyber_vision = 4.1.2cyber_vision = 4.1.3cyber_vision = 4.1.4cyber_vision = 4.1.5cyber_vision = 4.1.6cyber_vision = 4.1.7cyber_vision = 4.2.0cyber_vision = 4.2.1cyber_vision = 4.2.2cyber_vision = 4.2.3cyber_vision = 4.2.4cyber_vision = 4.2.6cyber_vision = 4.3.0cyber_vision = 4.3.1cyber_vision = 4.3.2cyber_vision = 4.3.3cyber_vision = 4.4.0cyber_vision = 4.4.1cyber_vision = 4.4.2cyber_vision = 4.4.3cyber_vision = 5.0.0cyber_vision = 5.0.1cyber_vision = 5.0.2cyber_vision = 5.1.0cyber_vision = 5.1.1cyber_vision = 5.1.2cyber_vision = 5.1.3cyber_vision = 5.2.0cyber_vision = 5.2.1cyber_vision = 5.3.0cyber_vision = 5.3.1cyber_vision = 5.3.2secure_firewall_threat_defense = 7.2.0secure_firewall_threat_defense = 7.2.0.1secure_firewall_threat_defense = 7.2.1secure_firewall_threat_defense = 7.2.2secure_firewall_threat_defense = 7.2.3secure_firewall_threat_defense = 7.2.4secure_firewall_threat_defense = 7.2.4.1secure_firewall_threat_defense = 7.2.5secure_firewall_threat_defense = 7.2.5.1secure_firewall_threat_defense = 7.2.5.2secure_firewall_threat_defense = 7.2.6secure_firewall_threat_defense = 7.2.7secure_firewall_threat_defense = 7.2.8secure_firewall_threat_defense = 7.2.8.1secure_firewall_threat_defense = 7.2.9secure_firewall_threat_defense = 7.2.10secure_firewall_threat_defense = 7.2.10.2secure_firewall_threat_defense = 7.3.0secure_firewall_threat_defense = 7.3.1secure_firewall_threat_defense = 7.3.1.1secure_firewall_threat_defense = 7.3.1.2secure_firewall_threat_defense = 7.4.0secure_firewall_threat_defense = 7.4.1secure_firewall_threat_defense = 7.4.1.1secure_firewall_threat_defense = 7.4.2secure_firewall_threat_defense = 7.4.2.1secure_firewall_threat_defense = 7.4.2.2secure_firewall_threat_defense = 7.4.2.3secure_firewall_threat_defense = 7.4.2.4secure_firewall_threat_defense = 7.4.3secure_firewall_threat_defense = 7.6.0secure_firewall_threat_defense = 7.6.1secure_firewall_threat_defense = 7.6.2secure_firewall_threat_defense = 7.6.2.1secure_firewall_threat_defense = 7.7.0secure_firewall_threat_defense = 7.7.10secure_firewall_threat_defense = 7.7.10.1unified_threat_defense_snort_intrusion_prevention_system_engine = 3.17.0sunified_threat_defense_snort_intrusion_prevention_system_engine = 3.17.1sunified_threat_defense_snort_intrusion_prevention_system_engine = 16.6.1unified_threat_defense_snort_intrusion_prevention_system_engine = 16.6.5unified_threat_defense_snort_intrusion_prevention_system_engine = 16.6.6unified_threat_defense_snort_intrusion_prevention_system_engine = 16.6.7aunified_threat_defense_snort_intrusion_prevention_system_engine = 16.6.9unified_threat_defense_snort_intrusion_prevention_system_engine = 16.6.10unified_threat_defense_snort_intrusion_prevention_system_engine = 16.12.1aUpgrade past the affected range:
snort 3.9.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20058Medium· 5.8Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error ch…
CVE-2026-20057Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This …
CVE-2026-20053Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checki…
CVE-2025-20312High· 7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability i…
CVE-2025-20359Medium· 6.5Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. …
CVE-2026-20154High· 8.6A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, rem…