CVE-2026-20006
CVE-2026-20006: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
1 advisory- Advisory severityMedium5.8
Medium [CVE-2026-20006] Cisco Secure Firewall Threat Defense Software TLS with Snort 3 Detection Engine Denial of Service Vulnerability
cisco-sa-ftd-tcp-dos-rHfqnwRgSource published Source updated
A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. This vulnerability is due to improper implementation of the TLS protocol. An attacker could exploit this vulnerability by sending a crafted TLS packet to an affected system. A successful exploit could allow the attacker to cause a device that is running Cisco Secure FTD Software to drop network…
- Related products — impact not confirmed
- Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0.1
- Cisco Secure Firewall Threat Defense (FTD) Software 7.2.1
- Cisco Secure Firewall Threat Defense (FTD) Software 7.2.2
- Cisco Secure Firewall Threat Defense (FTD) Software 7.2.3
4 more entries in the full advisory.
- Source-reported affected versions
- Scope: At the time of publication, this vulnerability affected Cisco products if they were running a vulnerable release of Cisco Secure FTD Software or Cisco FirePOWER Services and the following conditions were met:
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
- Workarounds
- As a workaround for this vulnerability, configure the device so that traffic from a specific TLS version is not blocked. To implement the workaround, complete the following steps:
- Log in to the Cisco Secure FMC Software web-based management interface.
- From the Policies menu, choose Access Control > SSL or Access Control > Decryption.
- Choose the appropriate SSL or decryption policy.
6 more entries in the full advisory.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.