Junglewise Threat Intelligence

CVE-2026-20290: Cisco Secure Firewall Threat Defense SSL/TLS denial of service in Snort 2

CVE-2026-20290 · Severity: medium · CVSS 5.8 · Published 2026-09-16

Executive brief

Cisco Secure Firewall Threat Defense (FTD) Software contains a flaw in how the Snort 2 detection engine processes SSL/TLS certificates. An attacker on the network can send a specially crafted SSL connection request that crashes the detection engine, temporarily disabling threat detection and network monitoring until the system restarts. This results in a denial-of-service condition that degrades network security oversight.

Technical details

The vulnerability is an incomplete validation flaw (CWE-805) in the Snort 2 Detection Engine's SSL/TLS certificate parsing logic. An unauthenticated, remote attacker can exploit this by sending a crafted SSL connection setup request that triggers improper handling in the certificate validation code. The attack requires only network reachability and no authentication; the malformed SSL certificate causes the Snort 2 process to crash and restart, resulting in a denial of service. Cisco has released software updates; no workarounds are available. Open Source Snort 2 has reached end of life and will not receive patches.

Affected products

  • Cisco Secure Firewall Threat Defense Multiple releases with Snort 2 configured (default on upgrades from 6.7.0 or earlier to 7.0.0+; deprecated in 7.7.0+)
  • Open Source Snort Snort 2 All versions; final release 2.9.20 (end of life)

Timeline

  • 2026-09-16: disclosed: Cisco Security Advisory published

References

Related threats