Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
Cisco has disclosed four critical flaws and one high-severity bug in its Secure Workload Software, a micro-segmentation tool. The two most severe issues, CVE-2026-20315 and CVE-2026-20317, are rated a perfect ten. Both problems stem from improper access control. Additional flaws include CVE-2026-20231, 9.9-rated for improper neutralization of special elements, and CVE-2026-20318, a 9.6 issue related to improper input validation.
The least severe flaw, CVE-2026-20319, is worth 7.5 points due to improper memory buffer restrictions. Cisco provides the tool as a SaaS service and for on-premises deployment. The company has patched the issues in its SaaS version, but users must upgrade the Agent and Connector tools for cloud usage. On-premises users need to update to version 3.10.9.1 for versions 3.10 or earlier, or to 4.0.4.16 for versions 4.0 or later.
Cisco discovered the vulnerabilities during an internal security review that used existing testing processes and AI models. The company has not observed any malicious use of the vulnerabilities.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.