Cisco appliance request parser inconsistency

Different request parsing paths can disagree about a protected route on affected appliances.

Published 28 Aug 2026Updated 1 Sep 202612 sources
CVSS 9.1

What happened

Two request parsing layers disagree about how a protected route is normalized.

Affected versions

Secure Access Appliance: 4.8.x Fixed: 4.8.7.

Why it matters

Edge appliances sit at a sensitive network boundary and are frequently accessible from less-trusted networks.

Detection & mitigation

  • Upgrade to version 4.8.7.
  • Restrict management interfaces.
  • Review reverse-proxy and appliance logs for normalization anomalies.

Public PoC references

No public PoC reference has passed the current publication threshold.