Anti-Malware Bypass Vulnerability in Cisco Secure Web Appliance
CVE-2026-20056
What is CVE-2026-20056?
A vulnerability exists in the Dynamic Vectoring and Streaming (DVS) Engine of Cisco AsyncOS Software for Cisco Secure Web Appliance. This security flaw could be exploited by an unauthorized, remote attacker to bypass the system's anti-malware scanner, thereby enabling the download of potentially malicious archive files. The exploitation is facilitated through the improper handling of specific archive files that should ideally be restricted. Although the malware could be downloaded onto an end user workstation, it will not execute automatically unless the end user extracts and runs the malicious file.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Web Appliance 11.8.0-453
Cisco Secure Web Appliance 12.5.3-002
Cisco Secure Web Appliance 12.0.3-007
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved