Impact
The vulnerability is rooted in improper input validation that allows malicious data to be injected into Cisco Secure Workload. This weakness, identified as CWE‑20, could enable an attacker to alter the normal operation of the software or potentially execute unauthorized commands. The CVSS score of 9.6 signals that the flaw is severe and could result in significant compromise of confidentiality, integrity, or availability if successfully exploited.
Affected Systems
The flaw exists in Cisco Secure Workload. Versions of the product released before the August 2026 hardening release are at risk; no firmware or software version numbers are disclosed in the advisory. All deployments of the product prior to receiving the hardening update remain potentially vulnerable.
Risk and Exploitability
Given the high CVSS score and the lack of available EPSS data, the potential for exploitation is considered high, though the exact probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through any untrusted input entry point exposed by Cisco Secure Workload, as improper validation may permit injection of malicious payloads. While no public exploit is currently known, the severity of the flaw warrants immediate attention to prevent possible compromise.
OpenCVE Enrichment