Junglewise Threat Intelligence

CVE-2026-20054: Cisco Snort 3 VBA decompression denial of service

CVE-2026-20054 · Severity: medium · CVSS 5.8 · Published 2026-03-04

Executive brief

Cisco Snort 3, a threat detection engine used in firewalls and routers to protect networks by analyzing incoming traffic for malicious patterns, contains a vulnerability in how it handles VBA (Visual Basic for Applications) macro decompression. An attacker can send specially crafted VBA data that causes the Snort 3 Detection Engine to crash or enter an infinite loop, disrupting the network's ability to inspect traffic and creating a denial-of-service condition on affected firewalls and security appliances.

Technical details

The vulnerability exists in the Snort 3 VBA decompression engine due to improper error checking when decompressing VBA macro data (CWE-122, CWE-369, CWE-786, CWE-835). An unauthenticated remote attacker can exploit this by sending crafted VBA data to the Snort 3 Detection Engine, causing it to enter an infinite loop or crash, resulting in a denial-of-service condition. The attack requires no authentication or user interaction and is reachable over the network from any system that can send traffic inspected by the affected device. VBA macro decompression is supported on IMAP, SMTP, HTTP, and POP3 inspection engines but is not enabled by default (only available starting with FTD 7.2.0). Cisco has released software updates to address these vulnerabilities.

Affected products

  • Cisco Snort 3 Multiple versions affected; fixed software available
  • Cisco Secure Firewall Threat Defense (FTD) 7.2.0 and later with Snort 3 enabled
  • Cisco IOS XE Releases with vulnerable Unified Threat Defense (UTD) Snort IPS Engine

Timeline

  • 2026-03-04: disclosed: Cisco Security Advisory published
  • patched: Software updates released by Cisco

References

Related threats