Home

Description

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. This vulnerability is due to improper handling of certain archive files. An attacker could exploit this vulnerability by sending a crafted archive file, which should be blocked, through an affected device. A successful exploit could allow the attacker to bypass the anti-malware scanner and download malware onto an end user workstation. The downloaded malware will not automatically execute unless the end user extracts and launches the malicious file. 

PUBLISHED Reserved 2025-10-08 | Published 2026-02-04 | Updated 2026-02-04 | Assigner cisco




MEDIUM: 4.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Problem types

Download of Code Without Integrity Check

Product status

Default status
unknown

11.8.0-453
affected

12.5.3-002
affected

12.0.3-007
affected

12.0.3-005
affected

14.1.0-032
affected

14.1.0-047
affected

14.1.0-041
affected

12.0.4-002
affected

14.0.2-012
affected

11.8.0-414
affected

12.0.1-268
affected

11.8.1-023
affected

11.8.3-021
affected

11.8.3-018
affected

12.5.1-011
affected

11.8.4-004
affected

12.5.2-007
affected

12.5.2-011
affected

14.5.0-498
affected

12.5.4-005
affected

12.5.4-011
affected

12.0.5-011
affected

14.0.3-014
affected

12.5.5-004
affected

12.5.5-005
affected

12.5.5-008
affected

14.0.4-005
affected

14.5.1-008
affected

14.5.1-016
affected

15.0.0-355
affected

15.0.0-322
affected

12.5.6-008
affected

15.1.0-287
affected

14.5.2-011
affected

15.2.0-116
affected

14.0.5-007
affected

15.2.0-164
affected

14.5.1-510
affected

12.0.2-012
affected

12.0.2-004
affected

14.5.1-607
affected

14.5.3-033
affected

15.0.1-004
affected

15.2.1-011
affected

14.5.0-673
affected

14.5.0-537
affected

12.0.1-334
affected

14.0.1-503
affected

14.0.1-053
affected

11.8.0-429
affected

14.0.1-040
affected

14.0.1-014
affected

12.5.1-043
affected

15.2.2-009
affected

15.5.0-566
affected

15.2.3-007
affected

15.5.0-574
affected

15.5.0-710
affected

15.2.4-022
affected

15.5.1-002
affected

References

sec.cloudapps.cisco.com/...co-sa-wsa-archive-bypass-Scx2e8zF (cisco-sa-wsa-archive-bypass-Scx2e8zF)

cve.org (CVE-2026-20056)

nvd.nist.gov (CVE-2026-20056)

Download JSON