Introduction to Cisco Secure Workload, SaaS Release 4.0.4.16

This document describes the features, bug fixes, and behavior changes, if any, for the Cisco Secure Workload software patch Release 4.0.4.16. This patch is associated with Cisco Secure Workload software major Release 4.0.1.1. For more information, see Cisco Secure Workload Release Notes, SaaS Release 4.0.1.1.


Note


Agents upgrade to this version will fail, unless cluster and agents are running at least 3.10.6.3 version.


Release Information

Release Version: 4.0.4.16

Published Date: July 6, 2026

New Software Features in Cisco Secure Workload, SaaS Release 4.0.4.16

Feature Name

Description

Operational Simplicity

Support for non-local Azure user accounts

The Azure AKS onboarding now supports clusters with Azure non-local account mode. This ensures AKS integrations continue as Azure transitions to non-local accounts by default. No change is needed for existing AKS clusters using local accounts.

For more information, see Azure Connector.

Support overlapping IP addressing across Kubernetes and public cloud scopes

Introduced support for overlapping pod/service CIDRs and VPC subnets across Kubernetes clusters and public cloud networks. This enables inventory classification by cluster identity or cloud attributes, distinguish traffic from environments with shared five-tuple, and builds isolated segmentation policies for each environment.

Amazon EKS authentication modes

Amazon EKS onboarding now supports newer authentication modes available in the EKS configuration workflow. This prevents onboarding and connectivity failures for clusters using newer EKS authentication settings and reduces upgrade risk as older authentication methods are deprecated.

For more information, see Back up and Restore Security Groups Using AWS Connector.

Backup and restore Cloud Security Groups in Google Cloud

Backup and restore support is now available for Cloud Security Groups in Google Cloud. You can preserve configurations and restore them during de-boarding, reducing operational risk during maintenance and recovery workflows.

For more information, see Back up and Restore Google Cloud VPC Firewall Rules Using GCP Connector.

Agent Enhancements

Support for Solaris

Secure Workload Agent now supports Solaris Branded zones (exclusive IP only).

Service Protection on Windows

Service Protection on Windows now also protects agent install folder files against modification.

Enhancements in Cisco Secure Workload, Release 4.0.4.16

  • A cloud-delivered Firewall Management Center (cdFMC) connector with one-click onboarding is now available for Cisco Security Cloud Control (SCC) customers who use both cdFMC and Cisco Secure Workload.

  • This release has been validated with Red Hat OpenShift 4.21.

  • This release has been validated with Kubernetes 1.36.

  • Upon rotation, agent logs are now archived and compressed into a zip file, allowing for a much larger history. The overall disk size for each process logging is still limited to 20MB.

  • Firewall content collection as part of remote logs download has been improved for Solaris 10 and Solaris 11 to include IPv6 table and the content of the address tables respectively. Also to collect the nftables in case agent enforced via nft on Linux.

  • Windows agent has been upgraded to use CiscoSSL 1.1.1.zg

  • Agent Linux daemonset image has been migrated to Redhat UBI 8 image. Because of this, most outstanding CVEs have been removed from the daemonset image.

  • Secure Workload agent now supports RedhatEnterpriseLinux Server 10 and Alma Linux 10 on x86_64 architecture.

Changes in Behavior in Cisco Secure Workload Release, 4.0.4.16

  • The Upgrade and Convert tabs have been removed from the agent UI dashboard. These actions are now available from the Agent List page. The upgrade feature now supports selecting a large set of agents at once.

  • On Agent uninstall, a copy of the agent log files will be stored in a zipped archive in/tmp and C:\Windows\Temp on Unix/Linux and Windows workloads respectively.

  • Changes to agent sensor_config file will be persisted across agent upgrades.

  • Per the agent EOL policy, we will begin revoking unsupported agent versions from downloads. Agent versions 3.9.x.x and older will no longer be visible in the UI or available through the agent installer script. If you have already downloaded the agent package, it can still be installed and registered to the cluster.

Resolved and Open Issues

The resolved and open issues for this release are accessible through the Cisco Bug Search Tool. This web-based tool provides you with access to the Cisco bug tracking system, which maintains information about issues and vulnerabilities in this product and other Cisco hardware and software products.


Note


You must have a Cisco.com account to log in and access the Cisco Bug Search Tool. If you do not have one, register for an account.


For more information about the Cisco Bug Search Tool, see the Bug Search Tool Help & FAQs.

Resolved Issues

Identifier

Headline

CSCwf43558 Services failures after upgrade with orchestrator dns name not resolvable.
CSCwj92795 IP fragments are not handled correctly by ipfilter on AIX
CSCwn73226 User uploaded SSL certs for UI are not honored during upgrade
CSCwn87775 Toggle button for consumer & provider swap is broken in 4.0 during Add/create policy
CSCwr66944 Vulnerabilities reported for 3.10.4.9 daemonset agent for Linux
CSCwt09269 Agent config profile is not getting applied
CSCwt22939 Add conjunctions (And/OR) on agents list page faceted filter
CSCwt24053 CSW Segmentation page - not able to click and select workspace
CSCwt30700 Segmentation Page filters do not always apply correctly (faceted filter keyboard navigation fix)

CSCwt33164

Reporting: PDF is not getting generated in the schedule PDF

CSCwt44997 CSW not able to bring up FMC connector with virtual patching
CSCwt46097 ERSPAN connector does not forward TCP flags to Secure Workload cluster
CSCwt51667 ACI connector profile the enforcement policies stay out of sync.
CSCwt52858 Excessive memory usage by EFE process.
CSCwt59646 YAML syntax error in group_vars template for ui_admin_password
CSCwt63772 Label management file upload does not accept UTF-8 encoding
CSCwt68467 Traffic getting dropped post 4.0 Patch 2 cluster upgrade
CSCwt91931 CSW Backup Failures and Persistent Restore Failures Due to HDFS Permission Denied in AWS/Azure Connectors
CSCwt97776 Customer reported scan of 4.0.3.13 Linux CSW agent shows vulnerabilities
CSCwu00711 Azure connector failing with error 400 while trying to update NSG of Azure Private Endpoint
CSCwu08300 Agent implemented DROP policies behavior discrepancy
CSCwu27982 Fix CVEs in 4.0.3.13 Windows CSW Agents
CSCwu34317 Solaris agent upgrade times out during package update
CSCwu36743 more than 3 filters on scope search is not working as expected
CSCwu44144 CSW Saas: Some change logs showing error when clicking datetime link
CSCwu44433 Agent does not block same-host NodePort traffic for DENY policies in Kubernetes/Openshift

CSCwu48507

On Solaris 11 forced upgrade causes issues

Open Issues

Identifier

Headline

CSCwn86124 Windows Agent - Missed Packets graph not being populated
CSCwo66813 Upgrade failing with VMMGR_CREATE_VMS_FAILURE
CSCwp95305 Windows Enforcement Agent Does Not Support Multiple Executables Per ANY Policy Rule

Contact Cisco Technical Assistance Center

If you cannot resolve an issue using the online resources listed above, contact Cisco TAC: