CVE-2026-20058Medium· 5.8▾ SunlitMultiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error ch…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
These vulnerabilities are due to improper error checking when decompressing VBA data. An attacker could exploit these vulnerabilities by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause the Snort 3 Detection Engine to unexpectedly restart, causing a DoS condition.
snort >= 3.0.0-233, < 3.9.6.0secure_firewall_threat_defense = 7.2.0secure_firewall_threat_defense = 7.2.0.1secure_firewall_threat_defense = 7.2.1secure_firewall_threat_defense = 7.2.2secure_firewall_threat_defense = 7.2.3secure_firewall_threat_defense = 7.2.4secure_firewall_threat_defense = 7.2.4.1secure_firewall_threat_defense = 7.2.5secure_firewall_threat_defense = 7.2.5.1secure_firewall_threat_defense = 7.2.5.2secure_firewall_threat_defense = 7.2.6secure_firewall_threat_defense = 7.2.7secure_firewall_threat_defense = 7.2.8secure_firewall_threat_defense = 7.2.8.1secure_firewall_threat_defense = 7.2.9secure_firewall_threat_defense = 7.2.10secure_firewall_threat_defense = 7.2.10.2secure_firewall_threat_defense = 7.3.0secure_firewall_threat_defense = 7.3.1secure_firewall_threat_defense = 7.3.1.1secure_firewall_threat_defense = 7.3.1.2secure_firewall_threat_defense = 7.4.0secure_firewall_threat_defense = 7.4.1secure_firewall_threat_defense = 7.4.1.1secure_firewall_threat_defense = 7.4.2secure_firewall_threat_defense = 7.4.2.1secure_firewall_threat_defense = 7.4.2.2secure_firewall_threat_defense = 7.4.2.3secure_firewall_threat_defense = 7.4.2.4secure_firewall_threat_defense = 7.4.3secure_firewall_threat_defense = 7.6.0secure_firewall_threat_defense = 7.6.1secure_firewall_threat_defense = 7.6.2secure_firewall_threat_defense = 7.6.2.1secure_firewall_threat_defense = 7.7.0secure_firewall_threat_defense = 7.7.10secure_firewall_threat_defense = 7.7.10.1unified_threat_defense_snort_intrusion_prevention_system_engine = 17.9.3aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.9.5aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.9.6unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.2unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.3unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.3aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.4unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.4aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.4bunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5unified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5bunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5cunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.5dunified_threat_defense_snort_intrusion_prevention_system_engine = 17.12.6unified_threat_defense_snort_intrusion_prevention_system_engine = 17.13.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.14.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.2aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.2cunified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.3unified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.3aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.4unified_threat_defense_snort_intrusion_prevention_system_engine = 17.15.4cunified_threat_defense_snort_intrusion_prevention_system_engine = 17.16.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.17.1unified_threat_defense_snort_intrusion_prevention_system_engine = 17.18.1unified_threat_defense_snort_intrusion_prevention_system_engine = 17.18.1aunified_threat_defense_snort_intrusion_prevention_system_engine = 17.18.2Upgrade past the affected range:
snort 3.9.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20057Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This …
CVE-2026-20054Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper error …
CVE-2026-20053Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checki…
CVE-2025-20359Medium· 6.5Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to cause the disclosure of possible sensitive data or cause the Snort 3 Detection Engine to crash. …
CVE-2026-20067Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…
CVE-2026-20066Medium· 5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…