Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-20006

20
FAUCET Score

CVE-2026-20006 is a medium-severity denial-of-service vulnerability affecting the Snort 3 Detection Engine within Cisco Secure Firewall Threat Defense (FTD) Software, specifically impacting TLS cryptography functionality (excluding TLS 1.3). An unauthenticated, remote attacker can exploit this flaw by sending a crafted TLS packet, causing the Snort 3 engine to restart and drop network traffic. While the attack complexity is low, leading to a DoS condition, there is currently no public exploit code, active exploitation, or significant community discussion beyond a single mention.

Impacted Technologies

VendorProductVersion(s)CPE
CiscoCisco Secure Firewall Threat Defense (FTD) Software
7.2.0, 7.2.0.1, 7.2.1, 7.2.10, 7.2.10.2, 7.2.2, 7.2.3, 7.2.4, 7.2.4.1, 7.2.5, 7.2.5.1, 7.2.5.2, 7.2.6, 7.2.7, 7.2.8, 7.2.8.1, 7.2.9, 7.3.0, 7.3.1, 7.3.1.1, 7.3.1.2, 7.4.0, 7.4.1, 7.4.1.1, 7.4.2, 7.4.2.1, 7.4.2.2, 7.4.2.3, 7.4.2.4, 7.6.0, 7.6.1, 7.6.2, 7.6.2.1CNA affecteddefault unknown

CVSS Data

CVSS version used by this source: 3.1

5.8MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
30.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 18th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

ciscopatch availablevia llm_extracted
Fixed in: 1.0
View patch
ciscoworkaround availablevia llm_extracted
View patch

Vendor Advisories (1)

ciscollm-cisco-1f6e59161a2723ccMEDIUM

Cisco Secure Firewall Threat Defense Software TLS with Snort 3 Detection Engine Denial of Service Vulnerability

Mar 4, 2026

References

sec.cloudapps.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tcp-dos-rHfqnwRg