[source: 2]Date: 2026/08/24
【Vulnerability Alert】4 Critical Security Vulnerabilities Found in Cisco Secure Workload
- Subject: 【Vulnerability Alert】4 Critical Security Vulnerabilities Found in Cisco Secure Workload
- Description:
- Forwarded from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC) Security Information Alert TWCERTCC-200-202608-00000017
- The Cisco Secure Workload development team identified multiple security vulnerabilities during internal security reviews and has completed patches for them. Currently, there is no evidence indicating that these vulnerabilities are being actively exploited. To assist customers in deploying security updates in a timely manner and to streamline the vulnerability disclosure process, Cisco has publicly released relevant vulnerability information and remediation advice.
- CVE-2026-20231 (CVSS: 9.9) is an Improper Neutralization of Special Elements vulnerability; CVE-2026-20315 (CVSS: 10.0) is an Incorrect Access Control vulnerability; CVE-2026-20317 (CVSS: 10.0) is an Improper Authentication vulnerability; CVE-2026-20318 (CVSS: 9.6) is an Improper Input Validation vulnerability.
- Affected Systems:
- Cisco Secure Workload versions 3.10 and earlier, Cisco Secure Workload version 4.0
- Recommendations:
- Please update to the following versions: Cisco Secure Workload version 3.10.9.1 or later, Cisco Secure Workload version 4.0.4.16 or later
- Reference:
Computer and Communication Center
Network System Division