ZeroHour
Product

Cisco Secure Workload

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.

Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.

Cisco Secure Workload Software Security Hardening Release: August 2026

Cisco shipped August 2026 hardening releases for Secure Workload fixing multiple internally discovered vulnerabilities that are not actively exploited.

Cisco's Secure Workload engineering team completed an internal security review that found multiple vulnerabilities during internal testing. The issues are grouped by CWE class with a single CVE assigned per grouping, and none are known to be actively exploited. Cisco has released hardening updates for customers to patch.

Cisco Security Advisories · 27d agoAdvisory

Related CVEs

  • Unauthenticated External File-System Control in Cisco Crosswork (CVSS 10.0)
    CVE-2026-20358 is an external control of the file system vulnerability (CWE-73) in Cisco Crosswork that Cisco's Crosswork engineering team discovered during an internal security review and addressed in a software hardening release announced for publication on August 19, 2026. Per the CVSS vector, it is exploitable remotely over the network without authentication or user interaction, and an attacker's ability to influence the file names or paths the software uses lets it operate on files outside its intended security scope. An attacker gains the ability to modify or overwrite files and disrupt the platform, with the score rating integrity and availability impact as high and confidentiality impact as none; the specific vulnerable interface or protocol is not described in the available data. At risk are organizations running Cisco Crosswork, and the companion advisory batch from the same date also patched flaws in Cisco Secure Workload, though no affected or fixed version numbers were provided in the available data. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
    · Cisco Crosswork · Cisco Secure Workloadmoderate
  • Missing Authentication for Critical Functions in Cisco Crosswork
    CVE-2026-20357 describes missing authentication for critical functions (CWE-306) in Cisco Crosswork, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the flaw requires no privileges and is reachable over the network with low attack complexity, an unauthenticated remote attacker could invoke critical functionality directly. The CVSS 10.0 score, with scope change and high confidentiality, integrity, and availability impacts, indicates successful attacks could compromise the Crosswork platform and spill over to other components it manages. Organizations running Cisco Crosswork — typically large enterprises and service providers using it for network automation — are affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
    · Cisco Crossworkniche
  • Improper Authentication Flaws in Cisco Secure Workload Score CVSS 10.0
    CVE-2026-20317 covers multiple improper authentication issues (CWE-287) in Cisco Secure Workload, discovered internally by Cisco's engineering team during a comprehensive security review and addressed in a software hardening release. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H) indicates the flaws are exploitable over the network by an unauthenticated attacker with no user interaction, and the changed scope means successful exploitation can affect components beyond the vulnerable one. An attacker could gain high-impact modification of system state and denial of service across the deployment, though the vector indicates no direct confidentiality (data disclosure) impact. Users of Cisco Secure Workload are affected; the fix was published as part of Cisco's August 19, 2026 advisory batch, which reportedly patched nine Crosswork and Secure Workload flaws, five of which scored CVSS 10.0. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days (37th percentile).
    · Cisco Secure Workloadniche
  • Unauthenticated SQL Injection (CWE-89) in Cisco Crosswork
    CVE-2026-20030 covers multiple SQL injection issues (CWE-89, improper neutralization of special elements used in SQL commands) in Cisco Crosswork, discovered by Cisco's own engineering team during a proactive internal security review and fixed in a dedicated software hardening release. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates an unauthenticated remote attacker could trigger the flaw by sending crafted input containing SQL special elements to a network-accessible component, with no user interaction required. The critical 10.0 score with scope changed (S:C) and high confidentiality, integrity, and availability impacts means a successful exploit could fully compromise the vulnerable component and potentially the wider system, allowing the attacker to run arbitrary SQL against the backing database, read or alter data, and disrupt service. Only organizations running Cisco Crosswork are affected by this CVE; the same August 19, 2026 advisory cycle also patched other Crosswork and Secure Workload flaws, five of which also scored CVSS 10.0. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days (44th percentile).
    · Cisco Crossworkniche
  • Unauthenticated Improper Access Control in Cisco Secure Workload
    CVE-2026-20315 covers improper access control weaknesses (CWE-284) in Cisco Secure Workload that were found by Cisco's own engineering team during an internal security review and fixed in a dedicated software hardening release. Per the CVSS 10.0 vector, the flaws are exploitable remotely by unauthenticated attackers with no user interaction or special conditions required. Because the scope is changed with high confidentiality, integrity, and availability impact, a successful attacker could bypass access restrictions and gain broad, potentially full control over affected Secure Workload components and their data. Any organization running Cisco Secure Workload is affected; the fix ships as part of Cisco's August 19, 2026 advisory batch, which also patched Crosswork flaws, five of which scored the maximum CVSS 10.0. There is no known exploitation, no public proof-of-concept, and no KEV listing, and EPSS estimates only a 0.4% chance of exploitation within the next 30 days.
    · Cisco Secure Workloadniche
  • Injection vulnerabilities (CWE-74) in Cisco Secure Workload
    CVE-2026-20231 bundles multiple injection-class vulnerabilities (CWE-74, improper neutralization of special elements) in Cisco Secure Workload, found by Cisco's own engineers during an internal security review and addressed in a software hardening release published alongside Cisco's August 19, 2026 advisories. The flaws are triggered remotely over the network by an authenticated, low-privileged user who submits input containing special elements that an affected component fails to neutralize. The CVSS 9.9 (critical) score, with a changed scope and high ratings for confidentiality, integrity, and availability, indicates a successful attack could compromise the vulnerable component and potentially extend to other components within the deployment. Only organizations running Cisco Secure Workload (formerly Tetration) are affected, and because valid low-privilege credentials and network access to the product's interfaces are required, exposure is concentrated in enterprise data-center environments. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists; EPSS currently estimates only a 0.5% chance of exploitation within 30 days.
    · Cisco Secure Workload (formerly Tetration)large
  • Improper Input Validation Bugs in Cisco Secure Workload (CVSS 9.6)
    Cisco has published a software hardening release for Cisco Secure Workload, its microsegmentation and workload-protection platform, fixing multiple internally discovered improper input validation vulnerabilities tracked as CVE-2026-20318 (CWE-20). An attacker with low-privileged (authenticated) access could send crafted input over the network, and because the software fails to properly validate it, could gain high-integrity control over data or configuration and disrupt availability of the affected component without any user interaction. The changed-scope metric in the CVSS vector (S:C) indicates the impact can extend beyond the vulnerable component's own security scope, though confidentiality is not listed as affected. Customers running Cisco Secure Workload are affected; related reporting notes the same August 19, 2026 advisory batch also patched Cisco Crosswork issues, but this CVE is scoped to Secure Workload. No public proof of concept or in-the-wild exploitation is known; the flaws came from Cisco's internal security review, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.
    · Cisco Secure Workloadmoderate
  • Buffer Management Flaws in Cisco Secure Workload Allow Remote Denial of Service
    CVE-2026-20319 describes a set of buffer management weaknesses (CWE-119) in Cisco Secure Workload, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. According to the CVSS vector, the flaws are remotely triggerable by unauthenticated attackers over the network, with low attack complexity and no user interaction required. The impact is to availability only: an attacker can cause a denial of service (high availability impact) with no effect on confidentiality or integrity. Organizations running Cisco Secure Workload are affected and should consult the Cisco advisory for the affected-release and fixed-release details. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.4% probability of exploitation within 30 days; it was published as part of Cisco's August 19, 2026 advisory batch, which also covered related Crosswork and Secure Workload flaws, though this particular issue scores 7.5 rather than the CVSS 10.0s in that release.
    · Cisco Secure Workloadmoderate
  • Unauthenticated XXE File Read in Cisco BroadWorks OCI-P Service
    CVE-2026-20320 is an XML External Entity (XXE) flaw (CWE-611) in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks, where external entity resolution is allowed by default and XML entries are improperly parsed. An unauthenticated remote attacker triggers it by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service on an affected system. A successful exploit lets the attacker view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user; confidentiality is impacted, with no integrity or availability effect (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). Only BroadWorks deployments whose OCI-P interface is reachable by the attacker are exposed, and the scope of affected releases is defined by Cisco's advisory. There is currently no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation within 30 days, indicating low near-term exploitation risk.
    · Cisco BroadWorks (Open Client Interface XML Parser / OCI-P service)mass
  • Authenticated Blind SQL Injection in Cisco Unified Intelligence Center Web Interface
    Cisco Unified Intelligence Center contains a blind SQL injection flaw (CWE-89) in its web-based management interface, caused by insufficient validation of user-supplied input. To trigger it, an attacker who already holds valid user credentials on the affected device sends a crafted request to the management interface. A successful exploit lets the attacker read the contents of the device's internal database, with no impact on integrity or availability. Any organization running Cisco Unified Intelligence Center is exposed, though the requirement for valid, low-privileged credentials raises the bar for exploitation. As of publication there is no known exploitation, no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%.
    · Cisco Unified Intelligence Center (web-based management interface)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.