CVE-2026-20057Medium· 5.8▾ SunlitMultiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to lack of proper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending a crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart causing a a denial of service (DoS) condition.
snort >= 3.0.0-233, < 3.9.3.0cyber_vision = 3.0.0cyber_vision = 3.0.1cyber_vision = 3.0.2cyber_vision = 3.0.3cyber_vision = 3.0.4cyber_vision = 3.0.5cyber_vision = 3.0.6cyber_vision = 3.1.0cyber_vision = 3.1.1cyber_vision = 3.1.2cyber_vision = 3.2.0cyber_vision = 3.2.1cyber_vision = 3.2.2cyber_vision = 3.2.3cyber_vision = 3.2.4cyber_vision = 4.0.0cyber_vision = 4.0.1cyber_vision = 4.0.2cyber_vision = 4.0.3cyber_vision = 4.1.0cyber_vision = 4.1.1cyber_vision = 4.1.2cyber_vision = 4.1.3cyber_vision = 4.1.4cyber_vision = 4.1.5cyber_vision = 4.1.6cyber_vision = 4.1.7cyber_vision = 4.2.0cyber_vision = 4.2.1cyber_vision = 4.2.2cyber_vision = 4.2.3cyber_vision = 4.2.4cyber_vision = 4.2.6cyber_vision = 4.3.0cyber_vision = 4.3.1cyber_vision = 4.3.2cyber_vision = 4.3.3cyber_vision = 4.4.0cyber_vision = 4.4.1cyber_vision = 4.4.2cyber_vision = 4.4.3cyber_vision = 5.0.0cyber_vision = 5.0.1cyber_vision = 5.0.2cyber_vision = 5.1.0cyber_vision = 5.1.1cyber_vision = 5.1.2cyber_vision = 5.1.3cyber_vision = 5.2.0cyber_vision = 5.2.1cyber_vision = 5.3.0cyber_vision = 5.3.1secure_firewall_threat_defense = 7.2.0secure_firewall_threat_defense = 7.2.0.1secure_firewall_threat_defense = 7.2.1secure_firewall_threat_defense = 7.2.2secure_firewall_threat_defense = 7.2.3secure_firewall_threat_defense = 7.2.4secure_firewall_threat_defense = 7.2.4.1secure_firewall_threat_defense = 7.2.5secure_firewall_threat_defense = 7.2.5.1secure_firewall_threat_defense = 7.2.5.2secure_firewall_threat_defense = 7.2.6secure_firewall_threat_defense = 7.2.7secure_firewall_threat_defense = 7.2.8secure_firewall_threat_defense = 7.2.8.1secure_firewall_threat_defense = 7.2.9secure_firewall_threat_defense = 7.2.10secure_firewall_threat_defense = 7.2.10.2secure_firewall_threat_defense = 7.3.0secure_firewall_threat_defense = 7.3.1secure_firewall_threat_defense = 7.3.1.1secure_firewall_threat_defense = 7.3.1.2secure_firewall_threat_defense = 7.4.0secure_firewall_threat_defense = 7.4.1secure_firewall_threat_defense = 7.4.1.1secure_firewall_threat_defense = 7.4.2secure_firewall_threat_defense = 7.4.2.1secure_firewall_threat_defense = 7.4.2.2secure_firewall_threat_defense = 7.4.2.3secure_firewall_threat_defense = 7.4.2.4secure_firewall_threat_defense = 7.4.3secure_firewall_threat_defense = 7.6.0secure_firewall_threat_defense = 7.6.1secure_firewall_threat_defense = 7.6.2secure_firewall_threat_defense = 7.6.2.1secure_firewall_threat_defense = 7.7.0secure_firewall_threat_defense = 7.7.10secure_firewall_threat_defense = 7.7.10.1unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.2unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.3unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.3aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.4unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.4aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.4bunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5bUpgrade past the affected range:
snort 3.9.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20058Medium· 5.8Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error ch…
CVE-2026-20054Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper error …
CVE-2026-20053Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checki…
CVE-2025-20359Medium· 6.5Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. …
CVE-2026-20067Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…
CVE-2026-20066Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…