Executive brief
Cisco Secure Workload is a cloud security platform used to protect and monitor containerized applications. This release addresses buffer management vulnerabilities that could allow an attacker with network access to cause a denial of service or potentially execute arbitrary code. The vulnerabilities were discovered internally and there is no evidence of active exploitation.
Technical details
CVE-2026-20319 is a buffer management issue classified under CWE-119, involving improper restriction of operations within the bounds of a memory buffer. The vulnerability affects Cisco Secure Workload in both SaaS and on-premises deployments, and is remotely exploitable over the network without requiring authentication or user interaction (CVSS vector: AV:N/AC:L/PR:N/UI:N). An attacker can achieve denial of service or arbitrary code execution depending on the specific underlying vulnerability. Cisco has released patched versions (3.10.9.1 for releases 3.10 and earlier, and 4.0.4.16 for release 4.0) and recommends customers upgrade the Cluster, Agent, and Connector software components.
Affected products
- Cisco Secure Workload 3.10 and earlier, 4.0
Timeline
- 2026-08-19: disclosed: Cisco advisory published for CVE-2026-20319 and related vulnerabilities
- 2026-08-19: patched: Fixed versions released: 3.10.9.1 and 4.0.4.16