CVE-2026-20317
A remote anonymous attacker can exploit multiple vulnerabilities in Cisco Secure Workload to execute arbitrary code, bypass security measures, escalate privileges, manipulate or disclose data, and potentially cause memory corruption and denial-of-service conditions.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote anonymous attackers to execute arbitrary code, bypass security measures, escalate privileges, manipulate or disclose data, and cause memory corruption or denial-of-service conditions.
- Who is affected
- All deployments of Cisco Secure Workload.
- Urgency
- High priority due to remote anonymous exploitability and severity of impacts including RCE and privilege escalation.
- Action
- Apply vendor security updates for CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319 immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-20317
Get an email if CVE-2026-20317 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Advisory coverage (6)
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workloadncsc-nl · 2026-08-21
- high[NEW] [high] Cisco Secure Workload: Multiple vulnerabilitiescert-bund · 2026-08-20
- unknownMultiple vulnerabilities in Cisco products (20 August 2026)cert-fr-avis · 2026-08-20
- criticalCVE-2026-20317: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Sec…nvd · 2026-08-19
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisoriescisco-psirt · 2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 2026cisco-psirt · 2026-08-19
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-20317)