News › security
By Zayden R., August 21, 2026
Cisco's Secure Workload Software has been hit with critical vulnerabilities, including two rated at a perfect 10 severity. Engineers must update to version 3.10.9.1 or 4.0.4.16 to mitigate these risks.
Cisco has announced the discovery of significant vulnerabilities in its Secure Workload Software, previously known as Tetration. This micro-segmentation tool, which is designed to prevent lateral movement of attackers within a network, has been found to contain four critical flaws and one high-severity bug. The most severe of these is CVE-2026-20315 and CVE-2026-20317, both rated at a perfect 10 in severity. These flaws pertain to improper access control, with Cisco indicating issues around authorization, authentication, and privilege bypassing.
Alongside these, CVE-2026-20231, rated 9.9, involves improper neutralization of special elements, leading to potential command, OS, and argument injection vulnerabilities. Another flaw, CVE-2026-20318, rated 9.6, is linked to improper input validation. Finally, CVE-2026-20319, with a severity of 7.5, deals with improper restriction of operations within memory buffers, including overflows and out-of-bounds writes.
Cisco has already addressed these vulnerabilities in its SaaS offering, but on-premises users need to act quickly. Those running version 3.10 or earlier must upgrade to 3.10.9.1, while users of version 4.0 or later should move to 4.0.4.16. The flaws were uncovered during an internal security review, leveraging advanced AI models, though thankfully, no malicious exploitation has been detected yet.
For engineers managing these deployments, the immediate task is to ensure that the necessary upgrades are applied to both the Agent and Connector tools. The severity of these issues underscores the importance of staying vigilant and maintaining updated systems to protect against potential threats.
The Linux Camp teaches these topics as hands-on labs on real virtual machines, verified as you type.