AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-20028

MEDIUM · CVSS 5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the network driver of Cisco Terminal Service Agent allows authenticated remote attackers to bypass firewall rules linked to their accounts by exploiting incorrect mapping of network connections to user accounts. This could enable attackers with user-level credentials to send specially crafted network traffic, potentially inheriting more permissive firewall rules from other users. Organizations using affected Cisco products should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20028
Severity
MEDIUM
CVSS
5
EPSS
0.25%
Cisco

Original NVD Description

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.