#VU122394 Download of code without integrity check in Cisco AsyncOS for Secure Web Appliance - CVE-2026-20056
Published: February 5, 2026
Cisco AsyncOS for Secure Web Appliance
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to software does not perform software integrity check in the Dynamic Vectoring and Streaming (DVS) Engine implementation. A remote attacker can use a specially crafted archive to bypass antimalware scanner and download malware onto an end user workstation.