VMTech
Discuss a project

Cisco issues fixes for nine critical Crosswork and Secure Workload flaws

Cisco issues fixes for nine critical Crosswork and Secure Workload flaws

Cisco has released security updates for nine vulnerabilities in its Crosswork platforms and Secure Workload software, including five flaws with the maximum CVSS score of 10.0. The vendor said the issues were discovered during its continuing internal security review and are not known to be actively exploited.

Four vulnerabilities affect Cisco Crosswork Data Gateway, Crosswork Network Controller and Crosswork Planning regardless of device configuration. They affect Crosswork Release 7.2.1 and earlier; Cisco addressed them in Release 7.2.1-SP.

Crosswork flaws include SQL injection and missing authentication

The Crosswork advisories cover CVE-2026-20030, an SQL injection vulnerability rated 10.0; CVE-2026-20357, a missing-authentication flaw for a critical function rated 10.0; and CVE-2026-20358, an external control of file system vulnerability also rated 10.0. CVE-2026-20359, rated 9.9, concerns insufficient protection of credentials.

These products support network operations and planning workflows, making version identification important for organisations using the affected Crosswork components. Cisco’s prescribed remediation for the affected release line is the 7.2.1-SP update.

Secure Workload patches cover SaaS and on-premises deployments

Cisco also fixed five vulnerability groups in Secure Workload SaaS and on-premises deployments. CVE-2026-20231, rated 9.9, covers improper neutralisation issues spanning command, operating-system and argument injection. CVE-2026-20315 and CVE-2026-20317 are each rated 10.0 and involve improper access controls and improper authentication, respectively.

The remaining Secure Workload issues are CVE-2026-20318, rated 9.6, involving input validation, path traversal and external path control, and CVE-2026-20319, rated 7.5, involving buffer overflows and out-of-bounds writes. For Secure Workload Release 3.10 and earlier, the fix is version 3.10.9.1; for Release 4.0, Cisco lists version 4.0.4.16.

Part of a broader hardening effort

The disclosures follow fixes for 12 Catalyst SD-WAN and IOS XE Software bugs issued about two weeks earlier. Cisco said its internal review has produced software-hardening releases addressing multiple internally discovered vulnerabilities. The broader Cisco vulnerability landscape is also reflected in Cisco vulnerability developments and security incidents, which tracks Cisco issues alongside other enterprise security developments.

Earlier in the month, Cisco warned that CVE-2026-20349, an 8.6-rated flaw in Secure Firewall ASA Software and Secure Firewall Threat Defense Software, had been exploited in the wild. Although Cisco has not reported active exploitation of the nine newly patched issues, security teams should inventory Crosswork and Secure Workload installations, confirm their release versions and apply the specified updates through their established change process.

#cisco#cybersecurity#vulnerability#patchmanagement
Open analytics
On the site 0 views
min read 3 21.08.2026
Instagram

Cisco issues fixes for nine critical Crosswork and Secure Workload flaws

Open the post on Instagram ↗