Cisco Snort 3 Vulnerability Leading to Sensitive Data Disclosure
Cisco has identified two critical vulnerabilities in the Snort 3 detection engine affecting various enterprise security products such as firewalls, threat defense systems, and edge platforms.
Cisco has identified two critical vulnerabilities in the Snort 3 detection engine affecting various enterprise security products such as firewalls, threat defense systems, and edge platforms.
These vulnerabilities, CVE-2026-20026 and CVE-2026-20027, could potentially allow unauthenticated remote attackers to access sensitive information or cause denial-of-service conditions by disrupting packet inspection capabilities.
The vulnerabilities are due to improper buffer handling when processing Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests.
CVE-2026-20026: Involves a buffer use-after-free condition, potentially leading to unexpected engine restarts, interrupting critical packet inspection. CVE-2026-20027: Exploits an out-of-bounds read vulnerability, allowing attackers to extract sensitive information from the Snort 3 data stream.
Both vulnerabilities have been rated with Medium severity, with CVSS base scores of 5.8 and 5.3, indicating network-accessible attack vectors requiring no authentication or user interaction.
The vulnerabilities are due to improper buffer handling when processing Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests.
The vulnerabilities impact Cisco's extensive security portfolio:
Open Source Snort 3 deployments: Immediate patching to version 3.9.6.0 is required. Cisco Secure Firewall Threat Defense (FTD) systems: New installations from version 7.0.0 run Snort 3 by default. Systems upgraded from earlier releases continue to run Snort 2. Cisco IOS XE-based security products, including Catalyst 8000 and 8500 series edge platforms and Integrated Services Routers, if the optional Unified Threat Defense module is installed and enabled.
The following fixes and updates are recommended:
Snort 3.9.6.0 for open-source deployments Hotfixes for FTD versions 7.0 and 7.2 available through the Software Center Updates for Cisco IOS XE scheduled for version 26.1.1 in February 2026
No workarounds currently exist to mitigate these vulnerabilities, making software updates the sole remediation path. Cisco encourages organizations to use the Software Checker tool to identify exposure and prioritize patch deployment. The Cisco Product Security Incident Response Team confirms no active exploitation or public disclosure at the time of advisory publication.
Based on reporting by GBHackers.
