Junglewise Threat Intelligence

CVE-2026-20053: Cisco Snort 3 VBA decompression denial of service

CVE-2026-20053 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Technologies: Cisco Snort 3, Cisco Secure Firewall Threat Defense, Cisco Catalyst 8000V Edge Software, Cisco Catalyst 8500L Edge Platforms, Cisco IOS XE, Cisco Catalyst 8300 Series Edge Platforms, Cisco Catalyst 8200 Series Edge Platforms. Vendors: Cisco.

Executive brief

Snort 3 is a network intrusion detection and prevention engine used in Cisco firewalls and routers to monitor traffic for malicious activity. A vulnerability in the VBA file decompression feature allows remote attackers to send crafted files that crash the detection engine, disabling security monitoring and creating a denial of service condition.

Technical details

The vulnerability exists in Snort 3's Visual Basic for Applications (VBA) decompression engine due to improper range checking when decompressing user-controlled VBA data. An unauthenticated, remote attacker can send crafted VBA data to trigger a heap buffer overflow, causing the Snort 3 Detection Engine to unexpectedly restart and resulting in a denial of service condition. The vulnerability affects multiple Cisco products running Snort 3, including Secure Firewall Threat Defense (FTD), IOS XE devices with Unified Threat Defense (UTD) enabled, and open-source Snort 3. VBA decompression is not enabled by default in FTD, but affects IMAP, SMTP, HTTP, and POP3 inspection engines when configured. Cisco has released software updates; workarounds are available.

Affected products

  • Cisco Snort 3 Open source releases (specific versions in advisory)
  • Cisco Secure Firewall Threat Defense 7.2.0 and later with Snort 3 enabled
  • Cisco IOS XE releases with Unified Threat Defense (UTD) Snort IPS Engine
  • Cisco Catalyst 8000V Edge Software vulnerable releases with UTD enabled
  • Cisco Catalyst 8200 Series Edge Platforms vulnerable releases with UTD enabled
  • Cisco Catalyst 8300 Series Edge Platforms vulnerable releases with UTD enabled
  • Cisco Catalyst 8500L Edge Platforms vulnerable releases with UTD enabled

Timeline

  • 2026-03-04: advisory: Cisco security advisory published (cisco-sa-ftd-snort3-vbavuls-96UcVVed)

References

Related threats