Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Cisco Secure Workload Software Flawed: A Critical Examination of the Micro-Segmentation Tool


Cisco Secure Workload Software has been found to have five nasty flaws, including four critical bugs with perfect scores of 10, 10, 9.9, and 9.6. The company has fixed the flaws with its SaaS, but users still need to upgrade the Agent and Connector tools needed to use the cloudy software. Organizations must take immediate action to patch the vulnerabilities and ensure that their networks are secure.

  • Cisco Secure Workload Software has been found to have five nasty flaws, including four critical bugs with perfect scores of 10, 10, 9.9, and 9.6.
  • The fifth bug has a score of 7.5 and relates to improper access control, special element neutralization, input validation, and memory buffer restrictions.
  • Cisco discovered the bugs after a comprehensive internal security review using existing testing processes and frontier AI models.
  • Users need to upgrade the Agent and Connector tools to use the cloud-based software, and some users need to upgrade to version 3.10.9.1 or 4.0.4.16.
  • No malicious use of the vulnerabilities has been detected, but the flaws can allow attackers to move laterally across a network and compromise sensitive data.
  • It is essential for organizations to patch the vulnerabilities and keep software up-to-date to prevent exploitation by attackers.



  • Cisco Secure Workload Software, a micro-segmentation tool formerly known as Tetration, has been found to have five nasty flaws, including four critical bugs with perfect scores of 10, 10, 9.9, and 9.6. The fifth bug, CVE-2026-20319, carries a score of 7.5. These flaws relate to improper access control, improper neutralization of special elements, improper input validation, and improper restriction of operations within the bounds of a memory buffer.

    The bugs were discovered by Cisco after a comprehensive internal security review, which involved existing testing processes as well as frontier AI models. The company has fixed the flaws with its SaaS, but users still need to upgrade the Agent and Connector tools needed to use the cloudy software.

    On-prem users who have deployed version 3.10 or earlier need to get to version 3.10.9.1. Users of version 4.0 or later need to adopt 4.0.4.16 sooner rather than later. The company has not offered much detail about either of the two perfect-ten-rated bugs, saying only that 20315 “covers authorization, authentication, privileges, and bypasses” and that 20317 has to do with “missing authentication, authentication bypass, and reliance on untrusted inputs.”

    The flaws were discovered after Cisco participated in Project Glasswing, which grants access to Anthropic’s too-powerful-for-public-release Mythos bug-finding model. So maybe that’s the frontier model involved in this research. Thankfully, Cisco says it has detected no malicious use of the vulnerabilities.

    The discovery of these flaws is a significant concern for organizations that rely on Cisco Secure Workload Software for network security. The flaws could potentially allow attackers to move laterally across a network, compromising sensitive data. It is essential for organizations to take immediate action to patch the vulnerabilities and ensure that their networks are secure.

    The fact that Cisco has fixed the flaws with its SaaS but still requires users to upgrade the Agent and Connector tools highlights the importance of keeping software up-to-date. It is crucial for organizations to regularly review their software and patch vulnerabilities to prevent exploitation by attackers.

    In conclusion, the discovery of the flaws in Cisco Secure Workload Software is a critical concern for organizations that rely on network security. The company's efforts to patch the vulnerabilities and provide guidance to users are a step in the right direction. However, it is essential for organizations to take immediate action to patch the vulnerabilities and ensure that their networks are secure.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Cisco-Secure-Workload-Software-Flawed-A-Critical-Examination-of-the-Micro-Segmentation-Tool-ehn.shtml

  • https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-reads-like-olympic-gymnastics-scores-10-10-99-96-and-75/5290838

  • https://nvd.nist.gov/vuln/detail/CVE-2026-20315

  • https://www.cvedetails.com/cve/CVE-2026-20315/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-20317

  • https://www.cvedetails.com/cve/CVE-2026-20317/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-20319

  • https://www.cvedetails.com/cve/CVE-2026-20319/


  • Published: Fri Aug 21 01:13:53 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us