{
  "id": 2313877,
  "title": "Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.",
  "url": "https://urgent.news/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T05:33:08.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838"
  },
  "original_language": "en",
  "account": "Cisco has identified four critical vulnerabilities and one high-severity flaw in its Secure Workload Software, a micro-segmentation tool. The two most severe bugs, CVE-2026-20315 and CVE-2026-20317, are rated a perfect 10 on the Common Vulnerability Scoring System, indicating they allow attackers to bypass authentication, authorization, and privileges, or rely on untrusted inputs.\n\nAnother bug, CVE-2026-20231, is rated 9.9 and relates to improper neutralization of special elements, which can lead to command, OS, or argument injection. The 9.6-rated flaw, CVE-2026-20318, is an improper input validation issue. Lastly, CVE-2026-20319, rated 7.5, stems from improper restriction of operations within memory buffers, potentially resulting in overflows and out-of-bounds writes.\n\nCisco has patched these flaws in its SaaS version, but users must upgrade their Agent and Connector tools to utilize the cloud-based software. On-premise users with versions 3.10 or earlier need to upgrade to 3.10.9.1, while those on versions 4.0 or later should update to 4.0.4.16. Cisco discovered the vulnerabilities through an internal security review involving existing processes and frontier AI models.\n\nThe company has not detected any malicious use of the vulnerabilities.",
  "summary": "Secure Workload Software has five nasty flaws and even SaaS users have updates to install",
  "key_points": [
    "Cisco identified four critical and one high-severity vulnerabilities in Secure Workload Software.",
    "Users must upgrade Agent and Connector tools to utilize cloud-based software with patches."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.",
        "url": "https://urgent.news/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-2318080",
        "published": "2026-08-21T05:33:08.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}