Skip to content

CVE-2026-20317 CVE-2026-20315 CVE-2026-20231 CVE-2026-20318 CVE-2026-20319

Cisco Secure Workload August 2026 hardening release fixes improper authentication and access control (CVE-2026-20317 et al.)

Critical 10.0 Vendor: Cisco Published

Cisco's August 2026 Secure Workload hardening release fixes several internally discovered improper authentication and access control vulnerabilities. Cisco reports no public disclosure or malicious use. Apply the hardening release; no workarounds exist.

What happened

Cisco's Secure Workload engineering team conducted an internal security review and released the August 2026 software hardening release. It addresses five internally discovered vulnerabilities. The most severe, CVE-2026-20317, is an improper authentication flaw with a CVSS 3.1 score of 10. It is reachable over the network with low attack complexity, requires no privileges or user interaction, and Cisco assesses the impact as no confidentiality loss but high integrity and availability loss.

CVE-2026-20315, an improper access control flaw also scored 10, is likewise reachable over the network with no privileges or user interaction, with high confidentiality, integrity and availability impact. CVE-2026-20231, scored 9.9, requires low privileges rather than none, and carries high impact across confidentiality, integrity and availability. CVE-2026-20318, scored 9.6, requires low privileges and affects integrity and availability but not confidentiality. CVE-2026-20319, scored 7.5, is an unauthenticated network issue with high availability impact only.

Cisco states it is not aware of any public announcements or malicious use of these vulnerabilities. No CISA Known Exploited Vulnerabilities entry is recorded for them.

Who is affected

The affected product is Cisco Secure Workload. The advisory lists eight affected builds: 2.2.1.41, 3.2.1.18, 3.3.2.50, 3.4.1.28, 3.4.1.34, 2.3.1.45, 2.3.1.41 and 3.3.2.28. Cisco has not provided a simpler before-version range, so compare your running build against this list directly. There is no statement limiting exposure to a particular deployment model or configuration.

What to do now

  1. Inventory your Cisco Secure Workload deployments and compare each running version against the eight affected builds listed above.
  2. Apply Cisco's August 2026 security hardening release. Cisco states a fix is available. The advisory data we hold does not include specific fixed version numbers, so confirm the exact target build in Cisco's advisory cisco-sa-hardening-csw1-shSvndWP before scheduling.
  3. Do not wait for a workaround. Cisco states there are no workarounds that address these vulnerabilities.
  4. If an immediate patch is not possible, restrict network reachability of the affected system to trusted networks and monitor for unexpected authentication or configuration changes.

Beyond the patch

Several of these flaws are reachable over the network without credentials, so the immediate question is whether your Secure Workload deployment is exposed where an attacker can reach it. Virtual CISO Services can help you map exposure before you patch, and Implementation & Assessment Services can verify that the hardening release is correctly applied and that equivalent authentication and input-validation issues are not present elsewhere.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-20317
Cisco Secure Workload
2.2.1.41
3.2.1.18
3.3.2.50
3.4.1.28
3.4.1.34
2.3.1.45
2.3.1.41
3.3.2.28
No fixed version listed yet
CVE-2026-20315
Cisco Secure Workload
2.2.1.41
3.2.1.18
3.3.2.50
3.4.1.28
3.4.1.34
2.3.1.45
2.3.1.41
3.3.2.28
No fixed version listed yet
CVE-2026-20231
Cisco Secure Workload
2.2.1.41
3.2.1.18
3.3.2.50
3.4.1.28
3.4.1.34
2.3.1.45
2.3.1.41
3.3.2.28
No fixed version listed yet
CVE-2026-20318
Cisco Secure Workload
2.2.1.41
3.2.1.18
3.3.2.50
3.4.1.28
3.4.1.34
2.3.1.45
2.3.1.41
3.3.2.28
No fixed version listed yet
CVE-2026-20319
Cisco Secure Workload
2.2.1.41
3.2.1.18
3.3.2.50
3.4.1.28
3.4.1.34
2.3.1.45
2.3.1.41
3.3.2.28
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.