Cisco Product Security Update Advisory

Cisco Product Security Update Advisory

Overview

Cisco has released a security update to address vulnerabilities found in Cisco products, specifically in Cisco Secure Workload Software. Users of these products should update to the latest version.

Affected Systems

  • Cisco Secure Workload Software versions earlier than 3.10.9.1.
  • Cisco Secure Workload Software versions earlier than 4.0.4.16.

Resolved Vulnerabilities

  • CVE-2026-20231: A command, OS command, and argument injection vulnerability in Cisco Secure Workload Software caused by failure to properly sanitize special characters (allowing a threat actor to inject commands).
  • CVE-2026-20315: A vulnerability caused by inadequate access control.
  • CVE-2026-20317: A vulnerability caused by inadequate authentication.
  • CVE-2026-20318: A vulnerability caused by inadequate input validation.
  • CVE-2026-20319: Buffer overflow and out-of-bounds write vulnerabilities caused by operations within memory buffer boundaries not being properly restricted.

Recommended Actions

  • Vulnerability Patches are available in the latest updates.
  • You must update to the latest version with the Vulnerability Patches following the instructions on the reference site.
  • The affected versions are Cisco Secure Workload Software 3.10.9.1 And 4.0.4.16.

Note

  • Cisco Secure Workload Software Security Hardening Release: August 2026.