CVE-2026-20028: A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the accou
A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.
This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-20028
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-200280.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20028 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for network driver of
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthori…nvd · 2026-07-14
- criticalCVE-2026-56188: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-07-14
- highCVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker…nvd · 2026-07-14
- highCVE-2026-54982: Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows …nvd · 2026-07-14
- criticalCVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execut…nvd · 2026-07-14
- highCVE-2026-42975: Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to…nvd · 2026-07-14
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07