Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

← Back to the feed

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

The Register · 3 hours ago

Cisco has disclosed five vulnerabilities in its Secure Workload Software (formerly Tetration), a micro-segmentation tool designed to prevent attackers from moving laterally across networks. Four of the flaws are rated critical, including two that scored a perfect 10 out of 10, making this a significant security concern for organisations relying on the product to contain network intrusions.

The two maximum-severity bugs, CVE-2026-20315 and CVE-2026-20317, both involve improper access control, covering authentication and authorisation bypasses. A third critical flaw, CVE-2026-20231, scored 9.9 and relates to injection issues, while CVE-2026-20318 (9.6) concerns improper input validation; a fifth, high-severity bug, CVE-2026-20319 (7.5), involves memory buffer handling. Cisco has already patched its SaaS offering, though users of that service still need to update the associated Agent and Connector tools, while on-premises users must upgrade to version 3.10.9.1 or 4.0.4.16 depending on their current release. Cisco said the flaws were found via internal review using "frontier AI models" and that no malicious exploitation has been detected.

  • Cisco Secure Workload Software has five flaws, two rated a perfect 10
  • SaaS users must update Agent/Connector tools; on-prem users need patches
  • No known exploitation; flaws found using AI-assisted internal security review

Software Technology

Read the full article at the source →