Cisco Product Security Update Advisory
Overview
Cisco has released a security update to address vulnerabilities found in Cisco products, specifically in Cisco Secure Workload Software. Users of these products should update to the latest version.
Affected Systems
- Cisco Secure Workload Software versions earlier than 3.10.9.1.
- Cisco Secure Workload Software versions earlier than 4.0.4.16.
Resolved Vulnerabilities
- CVE-2026-20231: A command, OS command, and argument injection vulnerability in Cisco Secure Workload Software caused by failure to properly sanitize special characters (allowing a threat actor to inject commands).
- CVE-2026-20315: A vulnerability caused by inadequate access control.
- CVE-2026-20317: A vulnerability caused by inadequate authentication.
- CVE-2026-20318: A vulnerability caused by inadequate input validation.
- CVE-2026-20319: Buffer overflow and out-of-bounds write vulnerabilities caused by operations within memory buffer boundaries not being properly restricted.
Recommended Actions
- Vulnerability Patches are available in the latest updates.
- You must update to the latest version with the Vulnerability Patches following the instructions on the reference site.
- The affected versions are Cisco Secure Workload Software 3.10.9.1 And 4.0.4.16.
Note
- Cisco Secure Workload Software Security Hardening Release: August 2026.