Junglewise Threat Intelligence

CVE-2026-20007: Cisco Secure Firewall Threat Defense Snort rules bypass

CVE-2026-20007 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Technologies: Cisco Secure Firewall Threat Defense. Vendors: Cisco.

Executive brief

Cisco Secure Firewall Threat Defense (FTD) is a network security appliance that uses Snort intrusion detection to block malicious traffic. A logic error in how Snort rules are evaluated allows attackers to craft packets that bypass configured security rules and gain unauthorized access to protected networks. This effectively disables critical security controls protecting corporate infrastructure.

Technical details

The vulnerability is a logic error (CWE-284: Improper Access Control) in the integration of Snort 2 and Snort 3 deep packet inspection engines with Cisco Secure FTD. When inspecting packets with nested or layered connections (inner and outer packets), different Snort rules may be applied inconsistently, allowing traffic to bypass configured rules. An unauthenticated remote attacker can send specially crafted packets to a targeted FTD device with an active intrusion policy and Snort enabled to exploit this flaw. Successful exploitation allows denied traffic to pass through to the protected network. Cisco has released software updates to address this vulnerability; no workarounds are available.

Affected products

  • Cisco Secure Firewall Threat Defense See Cisco Software Checker for affected versions

Timeline

  • 2026-03-04: disclosed

References

Related threats