Junglewise Threat Intelligence

CVE-2026-20028: Cisco Terminal Services Agent firewall rules bypass

CVE-2026-20028 · Severity: medium · CVSS 5 · Published 2026-08-05

Vendors: Cisco.

Executive brief

Cisco Terminal Services Agent is a network service component that manages remote access and enforces firewall policies per user account. A vulnerability in its network driver allows an authenticated attacker to bypass firewall rules by inheriting restrictions from other user accounts, potentially enabling unauthorized access or lateral movement within a protected network.

Technical details

The vulnerability is a privilege/account context confusion (CWE-266) in the network driver of Cisco Terminal Services Agent due to incorrect mapping of network connections to user accounts. An attacker with valid user-level credentials can send specially crafted network traffic to an affected device to exploit this flaw. The attack is network-based and requires authentication; a successful exploit allows the attacker to inherit firewall rules associated with a different user account, effectively bypassing account-based firewall restrictions. Cisco has released fixed version 1.4.3 for Terminal Services Agent software.

Affected products

  • Cisco Terminal Services Agent before 1.4.3

Timeline

  • 2026-08-05: disclosed
  • 2026-08-05: patched: Version 1.4.3 released

References