ZeroHour

CVE-2026-20319

moderate

Buffer Management Flaws in Cisco Secure Workload Allow Remote Denial of Service

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-20319 describes a set of buffer management weaknesses (CWE-119) in Cisco Secure Workload, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. According to the CVSS vector, the flaws are remotely triggerable by unauthenticated attackers over the network, with low attack complexity and no user interaction required. The impact is to availability only: an attacker can cause a denial of service (high availability impact) with no effect on confidentiality or integrity. Organizations running Cisco Secure Workload are affected and should consult the Cisco advisory for the affected-release and fixed-release details. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.4% probability of exploitation within 30 days; it was published as part of Cisco's August 19, 2026 advisory batch, which also covered related Crosswork and Secure Workload flaws, though this particular issue scores 7.5 rather than the CVSS 10.0s in that release.

What to do: Upgrade Cisco Secure Workload to the hardening/software release specified in the Cisco PSIRT advisory for CVE-2026-20319 (published August 19, 2026), since specific version numbers are not included in the available data. Review the advisory's affected-release table to confirm whether your deployment is in scope, and as an interim measure restrict network access to the affected components to reduce exposure to unauthenticated denial-of-service attempts. Continue monitoring Cisco PSIRT, as this release was part of a coordinated batch that also patched several maximum-severity Crosswork and Secure Workload flaws.

Affected
Cisco Secure Workload
Estimated exposure
moderatelikely tens of thousands of affected workload agent/server installations across enterprise data centers (no public install counts available) — Cisco Secure Workload is an agent-based enterprise microsegmentation platform typically deployed in large enterprise and data-center environments, and Cisco publishes no active-install figures, so this order-of-magnitude estimate rests on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20319 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119.

Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

Six Maximum

Cisco patched nine critical flaws, six rated CVSS 10.0, in Crosswork platforms and Secure Workload, none known to be exploited.

Cisco released fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, discovered during an internal security review that used advanced AI models. Six flaws carry CVSS 10.0 ratings, including SQL injection CVE-2026-20030 and missing authentication CVE-2026-20357 in Crosswork, and access control CVE-2026-20315 and authentication flaws CVE-2026-20317 in Secure Workload. Fixes shipped in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16. Cisco says no exploitation has been observed.

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0, found internally with no exploitation observed.

Cisco released fixes for four Crosswork platform vulnerabilities including CVE-2026-20030 SQL injection and CVE-2026-20357 missing authentication, both scoring CVSS 10.0, affecting Crosswork Release 7.2.1 and earlier. Five additional flaws in Secure Workload, including CVE-2026-20315 and CVE-2026-20317 at CVSS 10.0, affect SaaS and on-premises deployments up to releases 3.10 and 4.0. All issues were found through internal testing and are not known to be actively exploited. The patches follow a broader internal security review that recently addressed 12 Catalyst SD-WAN and IOS XE bugs.

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.

Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.