Junglewise Threat Intelligence

CVE-2026-20318: Cisco Secure Workload improper input validation

CVE-2026-20318 · Severity: critical · CVSS 9.6 · Published 2026-08-19

Technologies: Cisco Secure Workload. Vendors: Cisco.

Executive brief

Cisco Secure Workload is a software platform used to monitor and secure cloud workloads. A critical vulnerability in input validation allows remote attackers with no authentication to compromise the system's confidentiality, integrity, and availability. Cisco has released patches and recommends immediate upgrading.

Technical details

CVE-2026-20318 is an improper input validation vulnerability (CWE-20) in Cisco Secure Workload affecting both SaaS and on-premises deployments. The vulnerability has a CVSS score of 9.6 with a network attack vector, requiring no authentication or user interaction. An unauthenticated remote attacker can exploit this flaw to achieve high impact on confidentiality, integrity, and availability. The vulnerability was discovered during internal security testing and is not known to be exploited in the wild. Patches are available: upgrade to Secure Workload 3.10.9.1 or later for legacy releases, or 4.0.4.16 or later for version 4.0 and above.

Affected products

  • Cisco Secure Workload 3.10 and earlier, 4.0 before 4.0.4.16

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed releases: 3.10.9.1 and 4.0.4.16

References

Related threats