CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Cisco Patches Nine Critical Flaws in Crosswork and Secure Workload, Five Rated CVSS 10.0

August 21, 2026

Cisco has released security updates addressing nine vulnerabilities in its Crosswork platforms and Secure Workload software, with five of the flaws carrying a maximum CVSS score of 10.0. The patches are part of an ongoing internal security review that has already led to fixes for other products.

Four vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of device configuration. These include an SQL injection (CVE-2026-20030), a missing authentication for critical function (CVE-2026-20357), an external control of file system (CVE-2026-20358), and an insufficiently protected credentials issue (CVE-2026-20359). The flaws impact Crosswork Release 7.2.1 and earlier, with fixes available in version 7.2.1-SP.

Five additional vulnerabilities were patched in Cisco Secure Workload, affecting both SaaS and on-premises deployments. These include improper neutralization of special elements (CVE-2026-20231), improper access control (CVE-2026-20315), improper authentication (CVE-2026-20317), improper input validation (CVE-2026-20318), and improper restriction of operations within memory buffers (CVE-2026-20319). The vulnerabilities are fixed in Secure Workload 3.10.9.1 and 4.0.4.16.

Cisco stated that the vulnerabilities were discovered during internal testing and are not known to be actively exploited. However, the company urges customers to apply the updates promptly to mitigate potential risks. The announcement follows a similar advisory two weeks prior, where Cisco resolved 12 bugs in Catalyst SD-WAN and IOS XE Software.

Given the widespread deployment of Cisco equipment in enterprise networks, these vulnerabilities could be attractive targets for threat actors. Earlier this month, Cisco warned that a separate vulnerability in Secure Firewall ASA and FTD Software (CVE-2026-20349) had been exploited in the wild.

CVEs: CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359, CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319, CVE-2026-20349

Companies: Cisco

Products: Cisco Crosswork Data Gateway, Cisco Crosswork Network Controller, Cisco Crosswork Planning, Cisco Secure Workload, Cisco Secure Firewall ASA Software, Cisco Secure Firewall FTD Software