logo

Cisco Snort 3 Vulnerability Leading to Sensitive Data Disclosure

ID: 3636d7f6-e4a4-5f68-b45b-aa6da3f3f4c8

STIX ID: report--3636d7f6-e4a4-5f68-b45b-aa6da3f3f4c8

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Cisco disclosed two medium-severity Snort 3 vulnerabilities (CVE-2026-20026 — use-after-free causing engine restarts/DoS; CVE-2026-20027 — out-of-bounds read enabling data leakage) that impact open-source Snort 3 and multiple Cisco products (Secure Firewall/FTD, IOS XE with UTD, Meraki MX). Exploitation requires crafted DCE/RPC requests; Cisco reports no active exploitation, no mitigations besides patches, and provides fixes/hotfixes and scheduled updates — organizations should prioritize immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.