NewsSecurity Vulnerabilities

Multiple Cisco Products Snort 3 Distributed Computing Environment/Remote Procedure Call Vulnerabilities

CVE number CVE-2026-20026 and CVE-2026-20027

Multiple Cisco products are affected by vulnerabilities in the processing of Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, which would result in an interruption of packet inspection.

At the time of publication, these vulnerabilities affected Cisco Secure Firewall Threat Defense (FTD) Software if Snort 3 was configured.

On new installations of Cisco Secure FTD Software releases 7.0.0 and later, Snort 3 is running by default. On devices that were running Cisco Secure FTD Software Release 6.7.0 or earlier and were upgraded to Release 7.0.0 or later, Snort 2 is running by default.

At the time of publication, these vulnerabilities affected the following Cisco products if they were running a vulnerable release of Unified Threat Defense (UTD) Snort IPS Engine for Cisco IOS XE Software or UTD Engine for Cisco IOS XE SD-WAN Software:

  • 1000 Series Integrated Services Routers (ISRs)
  • 4000 Series ISRs
  • Catalyst 8000V Edge Software
  • Catalyst 8200 Series Edge Platforms
  • Catalyst 8300 Series Edge Platforms
  • Catalyst 8500L Edge Platforms
  • Cloud Services Routers 1000V
  • Integrated Services Virtual Routers

Note: UTD is not installed on these devices by default. If the UTD file is not installed, the device is not affected by these vulnerabilities.

At the time of publication, these vulnerabilities affected the following Cisco products if they were running a vulnerable release of Cisco Meraki software:

For further information please see – https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort3-dcerpc-vulns-J9HNF4tH

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.