Denial of Service Vulnerability in Cisco Snort 3 Detection Engine
CVE-2026-20066

5.8MEDIUM

Key Information:

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-20066?

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that allows an unauthenticated, remote attacker to disrupt packet inspection by causing the engine to restart. This issue arises from a flaw in the JSTokenizer normalization logic when handling JavaScript during HTTP inspections. By sending specially crafted HTTP packets through an established connection parsed by Snort 3, an attacker can force the engine to restart unexpectedly, leading to a denial of service condition. Note that the JSTokenizer feature is not enabled by default.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco Secure Firewall Threat Defense (FTD) Software 7.4.0

Cisco Secure Firewall Threat Defense (FTD) Software 7.4.1

Cisco Secure Firewall Threat Defense (FTD) Software 7.4.1.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.