CVE-2026-20056

CWE-4944 documents4 sources
Severity
4.0MEDIUM
EPSS
0.0%
top 93.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4

Description

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. This vulnerability is due to improper handling of certain archive files. An attacker could exploit this vulnerability by sending a crafted archive file, which should be blocked, through an affected device. A successful explo

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages1 packages

CVEListV5cisco/cisco_secure_web_appliance60 versions+59

🔴Vulnerability Details

2
CVEList
Cisco Secure Web Appliance TBD Bypass Vulnerability2026-02-04
GHSA
GHSA-5v8r-9wmj-294x: A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allo2026-02-04

📋Vendor Advisories

1
Cisco
Cisco Secure Web Appliance Real-Time Scanning Archive File Bypass Vulnerability2026-02-04
CVE-2026-20056 (MEDIUM CVSS 4) | A vulnerability in the Dynamic Vect | cvebase.io