Cisco product with CVSS 10.0 and access-control bypass enabling admin takeover; impacts many enterprises and merits broad IT notification.
CVE-2026-20315
Improper access control in Cisco Secure Workload allows unauthorized administrative access.
Is CVE-2026-20315 being exploited?
Not confirmed. CVE-2026-20315 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.41% probability of exploitation in the next 30 days.
How severe is CVE-2026-20315?
CVE-2026-20315 is rated Critical with a CVSS score of 10.0. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-20315?
Yes. A fix has been recorded for CVE-2026-20315. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-20315 affect?
CVE-2026-20315 affects Cisco Secure Workload. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-20315?
Apply Cisco Secure Workload hardening update immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Access-control bypass/privilege escalation enabling unauthorized admin actions, config changes, and data access/exfiltration.
Immediate action required
- affected2.2.1.41
- affected3.2.1.18
- affected3.3.2.50
- affected3.4.1.28
- affected3.4.1.34
- affected2.3.1.45
- affected2.3.1.41
- affected3.3.2.28
- affected3.1.1.59
- affected2.0.2.20
- affected2.1.1.33
- affected2.1.1.29
- affected3.2.1.28
- affected3.4.1.35
- affected3.1.1.65
- affected3.1.1.67
- affected2.0.1.34
- affected2.3.1.49
- affected2.2.1.39
- affected3.4.1.19
- affected3.3.2.23
- affected3.1.1.61
- affected3.1.1.54
- affected3.5.1.17
- affected3.3.2.33
- affected3.5.1.1
- affected2.3.1.53
- affected3.5.1.20
- affected3.5.1.30
- affected3.3.2.16
- affected3.1.1.55
- affected3.4.1.6
- affected2.3.1.50
- affected2.3.1.52
- affected3.2.1.19
- affected2.2.1.35
- affected3.1.1.53
- affected3.1.1.70
- affected3.2.1.20
- affected3.5.1.2
- affected1.103.1.12
- affected2.3.1.51
- affected3.3.2.42
- affected3.4.1.1
- affected3.3.2.12
- affected2.1.1.31
- affected3.5.1.23
- affected3.3.2.53
- affected3.4.1.14
- affected3.3.2.2
- affected3.4.1.20
- affected3.3.2.35
- affected2.2.1.34
- affected1.102.21
- affected3.3.2.5
- affected3.5.1.31
- affected3.6.1.5
- affected3.2.1.31
- affected3.5.1.37
- affected3.4.1.40
- affected3.6.1.17
- affected3.6.1.21
- affected3.2.1.32
- affected3.2.1.33
- affected3.6.1.35
- affected3.6.1.36
- affected3.7.1.5
- affected3.6.1.47
- affected3.7.1.22
- affected3.6.1.52
- affected3.7.1.39
- affected3.8.1.1
- affected3.7.1.51
- affected3.8.1.19
- affected3.8.1.36
- affected3.7.1.59
- affected3.8.1.39
- affected3.9.1.1
- affected3.9.1.10
- affected3.9.1.24
- affected3.9.1.25
- affected3.9.1.28
- affected3.9.1.38
- affected3.8.1.53
- affected3.9.1.52
- affected3.10.1.1
- affected3.9.1.64
- affected3.10.2.11
- affected3.9.1.66
- affected3.10.3.19
- affected3.9.1.69
- affected3.10.4.8
- affected3.10.5.6
- affected4.0.1.1
- affected4.0.2.4
- affected4.0.2.5
- affected3.10.6.3
- affected3.10.7.4
- affected4.0.3.13
- affected4.0.3.17
- affected3.10.8.3
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.