"These vulnerabilities were found during internal testing and are not known to be actively exploited," Cisco said, urging customers to apply the necessary updates to avoid future exposure.
Four critical Crosswork flaws spelled out by CVE
Cisco disclosed a quartet of high-severity vulnerabilities that affect its Crosswork portfolio — specifically Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning — regardless of device configuration. The company assigned four CVE identifiers and CVSS scores that underscore the urgency:
- CVE-2026-20030 (CVSS score: 10.0) — an SQL injection vulnerability
- CVE-2026-20357 (CVSS score: 10.0) — a missing authentication for critical function vulnerability
- CVE-2026-20358 (CVSS score: 10.0) — an external control of file system vulnerability
- CVE-2026-20359 (CVSS score: 9.9) — an insufficiently protected credentials vulnerability
The vendor reports these issues affect Cisco Crosswork Release version 7.2.1 and earlier. Cisco said the flaws have been addressed in Crosswork Release version 7.2.1-SP.
Five Secure Workload flaws — SaaS and on-premises — and their fixes
Cisco also patched five vulnerabilities impacting Cisco Secure Workload across software-as-a-service (SaaS) and on-premises deployments. The published CVE list names the technical classes and CVSS values:
- CVE-2026-20231 (CVSS score: 9.9) — improper neutralization of special elements spanning command, operating system, and argument injection
- CVE-2026-20315 (CVSS score: 10.0) — improper access control issues spanning authorization, authentication, privileges, and bypasses
- CVE-2026-20317 (CVSS score: 10.0) — improper authentication spanning missing authentication, authentication bypass, and reliance on untrusted inputs
- CVE-2026-20318 (CVSS score: 9.6) — improper input validation spanning input validation, path traversal, and external path control
- CVE-2026-20319 (CVSS score: 7.5) — improper restriction of operations within the bounds of a memory buffer spanning buffer overflows and out-of-bounds writes
According to Cisco’s advisory, the fixes are distributed to specific product releases: Secure Workload Release version 3.10 and earlier are fixed in 3.10.9.1; Secure Workload Release version 4.0 is fixed in 4.0.4.16.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadCisco’s internal review, prior hardening, and the broader context the company provided
Cisco characterized these patches as part of a "continued comprehensive internal security review" and noted the discoveries stem from internal testing. The vendor said this work follows a round of fixes about two weeks earlier, when Cisco resolved 12 bugs affecting Catalyst SD‑WAN and IOS XE Software. The company added that the internal review has "resulted in software hardening releases that address multiple internally discovered vulnerabilities."
The advisory also placed the recent disclosures against a background risk the company spelled out plainly: the prevalence of Cisco equipment in enterprise networks makes it an attractive target for malicious actors, and that attackers have repeatedly exploited dozens of Cisco product flaws to gain unauthorized access and deploy malware. Cisco further warned earlier in the month that a separate vulnerability—CVE-2026-20349 (CVSS score: 8.6) impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software—has been exploited in the wild.
What this means for technologists, affected enterprises, and adversaries
- Technologists and security teams: The company’s advisory urges applying the patched releases. For Crosswork, that means upgrading affected systems from Crosswork Release 7.2.1 and earlier to 7.2.1-SP. For Secure Workload, apply 3.10.9.1 for 3.10-series deployments and 4.0.4.16 for 4.0-series deployments.
- Affected enterprises and procurement leaders: Organizations that run Crosswork components or Secure Workload — in SaaS or on-premises form — should assess exposure based on the named releases and schedule updates promptly, given multiple CVEs scored at or near 10.0.
- Adversaries and threat actors: Cisco’s statement that the vulnerabilities were found during internal testing and are "not known to be actively exploited" does not remove incentive; the company itself cited the broad deployment of its gear as an enduring attraction for attackers who have a history of exploiting Cisco product flaws.
Cisco’s public disclosure is succinct and prescriptive: the company has cataloged the flaws, released patched builds, and urged customers to update. The advisory also links this wave of fixes to a broader internal hardening effort that produced earlier patches for other product lines. For organizations that rely on Crosswork or Secure Workload, the immediate task is unambiguous — evaluate versions in use, prioritize upgrades to the fixed builds, and record when those upgrades are completed.
https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html
