Secure Workload Software has five nasty flaws and even SaaS users have updates to install

Cisco has issued an advisory regarding five vulnerabilities discovered in its Secure Workload Software, a micro-segmentation tool previously known as Tetration. These flaws, identified during an internal security review that included the use of advanced AI models, range in severity from critical to high. Cisco confirmed that it has not observed any malicious exploitation of these vulnerabilities in the wild.
Among the most severe are two critical flaws, CVE-2026-20315 and CVE-2026-20317, both rated 10.0 on the CVSS scale. CVE-2026-20315 involves improper access control, encompassing issues with authorization, authentication, privileges, and bypasses. CVE-2026-20317 also relates to improper access control, specifically citing missing authentication, authentication bypass, and reliance on untrusted inputs.
Another critical vulnerability, CVE-2026-20231, received a CVSS score of 9.9. This flaw is described as an improper neutralization of special elements, which can lead to command, OS, or argument injection. Following this is CVE-2026-20318, rated 9.6, which stems from improper input validation.
The fifth vulnerability, CVE-2026-20319, is rated 7.5 and is considered high severity. It involves improper restriction of operations within the bounds of a memory buffer, potentially leading to overflows and out-of-bounds writes.
Cisco Secure Workload Software is available as both a Software-as-a-Service (SaaS) and an on-premise deployment. For SaaS users, Cisco has already patched the core service, but customers are still required to update their Agent and Connector tools to ensure full protection.
On-premise users need to take specific update actions based on their current version. Those running version 3.10 or earlier must upgrade to version 3.10.9.1. Users operating version 4.0 or later should update to version 4.0.4.16. The company emphasized the importance of applying these updates promptly.
Cisco's internal security review that uncovered these flaws reportedly leveraged "frontier AI models," which may include advanced tools like Anthropic’s Mythos bug-finding model, given Cisco's participation in Project Glasswing.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.