Executive brief
Cisco Secure Workload is a cloud security platform used to monitor and control application communications across hybrid and multi-cloud environments. Multiple critical vulnerabilities in the software could allow unauthenticated attackers to inject malicious commands, bypass access controls, or execute arbitrary code, potentially leading to full compromise of the deployment and unauthorized access to monitored infrastructure.
Technical details
CVE-2026-20231 represents improper neutralization of special elements (CWE-74), covering command injection, OS command injection, and argument injection vulnerabilities. The vulnerability affects Cisco Secure Workload software in both SaaS and on-premises deployments. Attack vector is network-based with no authentication required and no user interaction needed. An attacker can exploit this to inject and execute arbitrary commands on affected systems. Patches are available: upgrade to Secure Workload 3.10.9.1 or later for 3.10.x branch, and 4.0.4.16 or later for 4.0.x branch. Note that Cluster, Agent, and Connector components must all be upgraded.
Affected products
- Cisco Secure Workload 3.10 and earlier (3.10.9.1 is fixed), 4.0 through 4.0.4.15 (4.0.4.16 is fixed)
Timeline
- 2026-08-19: disclosed: Cisco Security Advisory published; vulnerabilities discovered during internal security review using frontier AI models
- 2026-08-19: patched: Fixed releases available: 3.10.9.1 and 4.0.4.16