PatchSiren

Cisco CVE debriefs · Page 6

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Cisco CVE published 2026-03-11

CVE-2026-20046

CVE-2026-20046 is a high-severity vulnerability in Cisco IOS XR Software that allows authenticated, local attackers to elevate privileges and gain full control of an affected device. The vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged account could exploit this vulnerability by using the CLI command to bypass the task group-ba [truncated]

HIGH Cisco CVE published 2026-03-11

CVE-2026-20040

CVE-2026-20040 is a high-severity vulnerability in the Command-Line Interface (CLI) of Cisco IOS XR Software. An authenticated, local attacker could exploit this vulnerability to execute arbitrary commands as root on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of user arguments passed to specific CLI commands. A low-privileged attacker could e [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20064

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T19:16:16.003Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Cisco Secure Firewall Threat Defense (FTD) Software, allowing an authenticated, local attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) con [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20024

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. This is due to heap corruption in OSPF when parsing packets. The CVE record was published on 2026-03-04T19:16:15.113Z and has not been modified since then. The NVD entry is [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20023

A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to corrupt memory on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to memory corruption when parsing OSPF protocol packets. An attacker could explo [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20021

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T19:16:12.150Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, allowing an authenticated adjacent attacker to exhaust memo [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20020

A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a DoS condition. If OSPF authentication is enabled, the attacker must know the secret key to exploit this vulnerability. The vulnerability is due to insufficient input validation when proc [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20016

A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid administrative credentials on an affected device. This vulnerability is due to insufficient [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20106

A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory resulting in a denial of service (DoS) condition requiring a manual reboot. This vulnerability is due to trusting user input without [truncated]

HIGH Cisco CVE published 2026-03-04

CVE-2026-20105

A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with a valid VPN connection to exhaust device memory resulting in a denial of service (DoS) condition. This vulnerability affects organizations using these products with Remote Access S [truncated]

HIGH Cisco CVE published 2026-03-04

CVE-2026-20103

The CVE-2026-20103 vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software, specifically in the Remote Access SSL VPN functionality. This vulnerability could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition to new Remote Access SSL VPN connections by exhausting device memory. The vulnerab [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20102

A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the SAML feature and access sensitive, browser-based information. This vulnerability is due to insufficient input validation of multiple HTTP paramete [truncated]

HIGH Cisco CVE published 2026-03-04

CVE-2026-20101

A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messag [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20068

A vulnerability in the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete error checking when parsing remote procedure call (RPC) data. An attacker could exploit this vulnerability by sending crafted RPC packets through an established connection [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20066

A vulnerability in the Snort 3 Detection Engine of multiple Cisco products could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. The vulnerability is due to an error in the JSTokenizer normalization logic when the HTTP inspection normalizes JavaScript. An attacker could exploit this vulnerability by sending craf [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20058

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T18:16:20.643Z and has not been modified since then. Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error checking when [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20054

A vulnerability in the Snort 3 VBA feature of multiple Cisco products could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper error checking when decompressing VBA data. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A successful exploit could allo [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20053

A vulnerability in the Snort 3 VBA feature of multiple Cisco products could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checking when decompressing VBA data, which is user controlled. An attacker could exploit this vulnerability by sending crafted VBA data to the Snort 3 Detection Engine on the targeted device. A suc [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20050

A vulnerability in the Do Not Decrypt exclusion feature of the SSL decryption feature of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management during the inspection of TLS 1.2 encrypted traffic. An attacker could exploit this vulnerabilit [truncated]

HIGH Cisco CVE published 2026-03-04

CVE-2026-20049

A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20044

A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this vulnerability by sending crafted input to the system CLI of the affected device. A successf [truncated]

HIGH Cisco CVE published 2026-03-04

CVE-2026-20039

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T18:16:17.140Z and has not been modified since then. This vulnerability affects Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, allowing an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20015

A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may impact the availability of services to devices elsewhere in the network. This vulnerability is due to a memory leak when parsing IKEv2 packets. An attacker could exploit this vulnerability by sending [truncated]

HIGH Cisco CVE published 2026-03-04

CVE-2026-20014

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-04T18:16:15.557Z and has not been modified since then. The vulnerability exists in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software, allowing an authenticated, remote attacker with valid VPN user credentials to cause a DoS condition on an affected device. This ma [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20013

A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to memory exhaustion caused by not freeing memory during IKEv2 packet processing. An attacker c [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20008

A vulnerability exists in certain CLI commands used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software, allowing an authenticated, local attacker to craft Lua code executable as root. User-provided input is not properly sanitized, enabling an attacker to inject Lua code via a malicious CLI command parameter. Successful exploitation r [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20007

A vulnerability in Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network that should have been dropped. This vulnerability is due to a logic error in the integration of the Snort Engine rules with Cisco Secure FTD Software. An attacker could exploi [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20006

A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper implementation of the TLS protocol. An attacker could exploit this v [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20003

The CVE-2026-20003 vulnerability in Cisco Secure FMC Software's REST API allows authenticated, remote attackers to conduct SQL injection attacks due to inadequate validation of user-supplied input. Successful exploitation requires valid user credentials with specific roles and could allow read access to the database and certain files on the underlying operating system. Organizations should prioritize patc [truncated]

MEDIUM Cisco CVE published 2026-03-04

CVE-2026-20005

A vulnerability in the Snort 3 Detection Engine could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerability is due to incomplete parsing of SSL handshake ingress packets. An attacker could exploit this vulnerability by sending crafted SSL handshake packets. A successful exploit could allow the attac [truncated]