Buffer Handling Vulnerability in Cisco's Snort 3 Detection Engine
CVE-2026-20026
5.8MEDIUM
What is CVE-2026-20026?
Multiple Cisco products are vulnerable due to flawed buffer handling when processing DCE/RPC requests. An unauthenticated, remote attacker can exploit this flaw to trigger a use-after-free condition, enabling them to send numerous DCE/RPC requests that could lead to sensitive information leaks or unexpectedly restart the Snort 3 Detection Engine, causing potential denial of service interruptions.
Affected Version(s)
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1
Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1