CVE-2026-20318

CRITICALCVSS 9.6/10EPSS 0.26%

Last modified

CVE-2026-20318 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.

Metrics

EPSS Probability
0.26%

18.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
CiscoCisco Secure Workload2.2.1.41; 3.2.1.18; 3.3.2.50; 3.4.1.28; 3.4.1.34; 2.3.1.45; 2.3.1.41; 3.3.2.28; 3.1.1.59; 2.0.2.20; 2.1.1.33; 2.1.1.29; 3.2.1.28; 3.4.1.35; 3.1.1.65; 3.1.1.67; 2.0.1.34; 2.3.1.49; 2.2.1.39; 3.4.1.19; 3.3.2.23; 3.1.1.61; 3.1.1.54; 3.5.1.17; 3.3.2.33; 3.5.1.1; 2.3.1.53; 3.5.1.20; 3.5.1.30; 3.3.2.16; 3.1.1.55; 3.4.1.6; 2.3.1.50; 2.3.1.52; 3.2.1.19; 2.2.1.35; 3.1.1.53; 3.1.1.70; 3.2.1.20; 3.5.1.2; 1.103.1.12; 2.3.1.51; 3.3.2.42; 3.4.1.1; 3.3.2.12; 2.1.1.31; 3.5.1.23; 3.3.2.53; 3.4.1.14; 3.3.2.2; 3.4.1.20; 3.3.2.35; 2.2.1.34; 1.102.21; 3.3.2.5; 3.5.1.31; 3.6.1.5; 3.2.1.31; 3.5.1.37; 3.4.1.40; 3.6.1.17; 3.6.1.21; 3.2.1.32; 3.2.1.33; 3.6.1.35; 3.6.1.36; 3.7.1.5; 3.6.1.47; 3.7.1.22; 3.6.1.52; 3.7.1.39; 3.8.1.1; 3.7.1.51; 3.8.1.19; 3.8.1.36; 3.7.1.59; 3.8.1.39; 3.9.1.1; 3.9.1.10; 3.9.1.24; 3.9.1.25; 3.9.1.28; 3.9.1.38; 3.8.1.53; 3.9.1.52; 3.10.1.1; 3.9.1.64; 3.10.2.11; 3.9.1.66; 3.10.3.19; 3.9.1.69; 3.10.4.8; 3.10.5.6; 4.0.1.1; 4.0.2.4; 4.0.2.5; 3.10.6.3; 3.10.7.4; 4.0.3.13; 4.0.3.17; 3.10.8.3

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-20318?
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20318 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
How severe is CVE-2026-20318?
CVE-2026-20318 has a CVSS score of 9.6/10 (CRITICAL severity). The EPSS model estimates a 0.26% probability of exploitation in the next 30 days.
How do I fix CVE-2026-20318?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-20318?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST