Assessment
Why it matters
Critical technical severity and a public proof of concept are meaningful, but confirmed exploitation and KEV evidence are not yet present.
Who should care
- Network security teams
- Cisco Secure Firewall operators
- Teams responsible for exposed security appliances
Response plan
What I would do
- Map affected appliances and software versions.
- Verify exposure to untrusted networks.
- Test and schedule the fixed release.
- Increase monitoring for anomalous traffic.
- Reassess if exploitation is confirmed.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-787: Out-of-bounds Write
- Affected versions
- Demonstration range: selected Secure Firewall releases
- Published
- 16 Aug 2026
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- Advisory published
- Proof of concept observed
- EPSS increased
- Signal increased to 76