Cisco’s Secure Workload Software Faces Multiple Critical Vulnerabilities

Cisco has identified several significant vulnerabilities in its Secure Workload Software, impacting both SaaS and on-premises users. Immediate updates are required to mitigate these risks.

Cisco has disclosed serious vulnerabilities in its Secure Workload Software, a tool designed to prevent lateral movement by attackers within networks. This software, previously known as Tetration, has four critical flaws and one high-severity issue that users must address.

Details of the Vulnerabilities

The vulnerabilities are rated with varying severity levels, with two classified as perfect tens. The first two critical flaws are identified as CVE-2026-20315 and CVE-2026-20317, both related to improper access control. Cisco has provided limited details, stating that CVE-2026-20315 involves issues with authorization, authentication, privileges, and bypasses, while CVE-2026-20317 pertains to missing authentication, authentication bypass, and reliance on untrusted inputs.

The next vulnerability, rated at 9.9, is CVE-2026-20231, which involves improper neutralization of special elements, covering command, OS, and argument injection. Following this is CVE-2026-20318, rated at 9.6, which addresses an improper input validation issue. Lastly, CVE-2026-20319 is rated at 7.5 and relates to improper restriction of operations within memory bounds, including buffer overflows and out-of-bounds writes.

Affected Users and Required Actions

Cisco offers Secure Workload Software as both a SaaS solution and for on-premises deployment. The company has already patched the SaaS version, but users must still update their Agent and Connector tools to utilize the cloud service effectively. For on-premises users, those running version 3.10 or earlier need to upgrade to version 3.10.9.1, while users of version 4.0 or later should move to version 4.0.4.16 promptly.

Discovery and Context

Cisco announced these vulnerabilities following a comprehensive internal security review, which included existing testing processes and possibly advanced AI models. The company is known to participate in Project Glasswing, which utilizes Anthropic’s advanced bug-finding model. As of now, Cisco has reported no evidence of malicious exploitation of these vulnerabilities.

Conclusion

With these vulnerabilities posing significant risks, affected users are urged to take immediate action to secure their systems. The prompt application of patches is essential to mitigate potential threats associated with these flaws.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 356