Cisco's Secure Workload Software Found to Have Five Security Flaws
Cisco's Secure Workload Software, a tool for micro-segmentation and preventing attackers from moving laterally across a network, has been found to have five security flaws. The company revealed this on Thursday after conducting a comprehensive internal security review that involved existing testing processes as well as frontier AI models.
The two most critical bugs are CVE-2026-20315 and CVE-2026-20317, both of which relate to improper access control. Cisco has not offered much detail about these flaws but described them as covering authorization, authentication, privileges, and bypasses for the first bug, and missing authentication, authentication bypass, and reliance on untrusted inputs for the second.
The other three bugs are CVE-2026-20318, a 9.6-rated improper input validation problem; CVE-2026-20231, a 9.9-rated flaw related to 'Improper neutralization of special elements (covers command, OS, argument injection)'; and CVE-2026-20319, a 7.5-rated issue with 'Improper restriction of operations within the bounds of a memory buffer', including overflows and out-of-bounds writes.
Cisco has fixed these flaws in its SaaS service but users still need to upgrade their Agent and Connector tools to continue using it. On-prem users who have deployed version 3.10 or earlier must get to version 3.10.9.1, while those with version 4.0 or later need to adopt 4.0.4.16.