Junglewise Threat Intelligence

CVE-2026-20231: Cisco Secure Workload improper neutralization of special elements

CVE-2026-20231 · Severity: critical · CVSS 9.9 · Published 2026-08-19

Technologies: Cisco Secure Workload. Vendors: Cisco.

Executive brief

Cisco Secure Workload is a cloud security platform used to monitor and control application communications across hybrid and multi-cloud environments. Multiple critical vulnerabilities in the software could allow unauthenticated attackers to inject malicious commands, bypass access controls, or execute arbitrary code, potentially leading to full compromise of the deployment and unauthorized access to monitored infrastructure.

Technical details

CVE-2026-20231 represents improper neutralization of special elements (CWE-74), covering command injection, OS command injection, and argument injection vulnerabilities. The vulnerability affects Cisco Secure Workload software in both SaaS and on-premises deployments. Attack vector is network-based with no authentication required and no user interaction needed. An attacker can exploit this to inject and execute arbitrary commands on affected systems. Patches are available: upgrade to Secure Workload 3.10.9.1 or later for 3.10.x branch, and 4.0.4.16 or later for 4.0.x branch. Note that Cluster, Agent, and Connector components must all be upgraded.

Affected products

  • Cisco Secure Workload 3.10 and earlier (3.10.9.1 is fixed), 4.0 through 4.0.4.15 (4.0.4.16 is fixed)

Timeline

  • 2026-08-19: disclosed: Cisco Security Advisory published; vulnerabilities discovered during internal security review using frontier AI models
  • 2026-08-19: patched: Fixed releases available: 3.10.9.1 and 4.0.4.16

References

Related threats