ZeroHour

CVE-2026-20315

niche

Unauthenticated Improper Access Control in Cisco Secure Workload

CVSS 3.1
10.0 critical
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-20315 covers improper access control weaknesses (CWE-284) in Cisco Secure Workload that were found by Cisco's own engineering team during an internal security review and fixed in a dedicated software hardening release. Per the CVSS 10.0 vector, the flaws are exploitable remotely by unauthenticated attackers with no user interaction or special conditions required. Because the scope is changed with high confidentiality, integrity, and availability impact, a successful attacker could bypass access restrictions and gain broad, potentially full control over affected Secure Workload components and their data. Any organization running Cisco Secure Workload is affected; the fix ships as part of Cisco's August 19, 2026 advisory batch, which also patched Crosswork flaws, five of which scored the maximum CVSS 10.0. There is no known exploitation, no public proof-of-concept, and no KEV listing, and EPSS estimates only a 0.4% chance of exploitation within the next 30 days.

What to do: Apply the Cisco Secure Workload software hardening release referenced in the August 19, 2026 advisory, checking the Cisco PSIRT advisory for the fixed version matching your deployment type (SaaS or on-premises), since specific fixed-version numbers are not provided in this data. Until patched, restrict network reachability of Secure Workload management interfaces and monitor Cisco advisories for updates. Given the maximum 10.0 severity and unauthenticated network vector, treat patching as urgent even though no exploitation is currently known.

Affected
Cisco Secure Workload
Estimated exposure
nicheunknown precisely; plausibly on the order of thousands of enterprise deployments (with many more agent-protected workloads per deployment) — Cisco publishes no install-base figures for Secure Workload (formerly Tetration), a specialized enterprise microsegmentation platform rather than a consumer or mass-market product, so the estimate reflects its limited enterprise-only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Six Maximum

Cisco patched nine critical flaws, six rated CVSS 10.0, in Crosswork platforms and Secure Workload, none known to be exploited.

Cisco released fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, discovered during an internal security review that used advanced AI models. Six flaws carry CVSS 10.0 ratings, including SQL injection CVE-2026-20030 and missing authentication CVE-2026-20357 in Crosswork, and access control CVE-2026-20315 and authentication flaws CVE-2026-20317 in Secure Workload. Fixes shipped in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16. Cisco says no exploitation has been observed.

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0, found internally with no exploitation observed.

Cisco released fixes for four Crosswork platform vulnerabilities including CVE-2026-20030 SQL injection and CVE-2026-20357 missing authentication, both scoring CVSS 10.0, affecting Crosswork Release 7.2.1 and earlier. Five additional flaws in Secure Workload, including CVE-2026-20315 and CVE-2026-20317 at CVSS 10.0, affect SaaS and on-premises deployments up to releases 3.10 and 4.0. All issues were found through internal testing and are not known to be actively exploited. The patches follow a broader internal security review that recently addressed 12 Catalyst SD-WAN and IOS XE bugs.

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.

Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.