Two critical vulnerabilities have been discovered in Cisco's Snort 3 detection engine, affecting a wide range of Cisco products including Cisco Secure Firewall Threat Defense, open-source Snort 3, Cisco IOS XE with Unified Threat Defense, and Cisco Meraki appliances. These flaws, identified as CVE-2026-20026 and CVE-2026-20027, stem from improper handling of Distributed Computing Environment/Remote Procedure Call (DCE/RPC) requests, allowing unauthenticated remote attackers to either disrupt packet inspection services or extract sensitive information from affected systems. The vulnerabilities are particularly concerning for organizations running Snort 3 on Cisco Secure FTD releases 7.0.0 and later, where Snort 3 is enabled by default, significantly expanding the attack surface.
The first vulnerability (CVE-2026-20026) is a use-after-free condition that can trigger denial of service by causing unexpected engine restarts, while the second (CVE-2026-20027) is an out-of-bounds read that could lead to sensitive data leakage. Cisco has released software updates to address these issues, but no workarounds are available. The vulnerabilities can be exploited by sending specially crafted DCE/RPC requests through monitored network connections, and no authentication is required for exploitation, making internet-facing systems especially at risk. Organizations are urged to apply the available patches promptly to mitigate potential threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco made fixed software available, including Snort 3.9.6.0 and hot fixes for affected Secure Firewall Threat Defense releases. The vendor urged customers to upgrade promptly to mitigate the vulnerabilities.
Cisco published a security advisory for two critical Snort 3 Distributed Computing Environment/Remote Procedure Call vulnerabilities, CVE-2026-20026 and CVE-2026-20027. The flaws affect multiple Cisco products, including Secure Firewall Threat Defense, IOS XE with Unified Threat Defense, Meraki appliances, and open-source Snort 3, and could allow unauthenticated attackers to disrupt inspection or access sensitive information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.