CVE-2026-20053
published 2026-03-04CVE-2026-20053: Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3…
PriorityP336medium5.8CVSS 3.1
AVNACLPRNUINSCCNINAL
EPSS
0.41%
33.6th percentile
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause an overflow of heap data, which could cause a DoS condition.
Affected
121 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
| cisco | cisco_cyber_vision | — | — |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
vendor_cisco·2026-03-04·CVSS 5.8
CVE-2026-20053 [MEDIUM] CWE-122 Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort 3 Visual Basic for Applications (VBA) Decompression Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort3-vbavuls-96UcVVed
This advisory is part o
Cisco
Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2026-20053 Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
CVE-2026-20053: Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort 3 Visual Basic for Applications (VBA) Decompression Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-122, CWE-369, CWE-786, CWE-122, CWE-369, CWE-786, CWE-835, CWE-122, CWE-369, CWE-786, CWE-122, CWE-369, CWE-786, CWE-835
Bug IDs: CSCwq23369, CSCwq23372, CSCwq23373, CSCwq23369, CSCwq23372
GHSA
GHSA-6wj9-h5wq-gm77: Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the S
ghsa_unreviewed·2026-03-04
CVE-2026-20053 [MEDIUM] CWE-122 GHSA-6wj9-h5wq-gm77: Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the S
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.
This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allow the attacker to cause an overflow of heap data, which could cause a DoS condition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-04
Published