mimile
Back to feed

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0

Cisco released security updates for Crosswork platforms and Secure Workload Software, fixing nine vulnerabilities including five with a CVSS score of 10.0. The flaws affect Crosswork Release 7.2.1 and earlier, and Secure Workload versions 3.10 and 4.0. Cisco said the vulnerabilities were found during internal testing and are not known to be actively exploited.

Key Facts

  • Four vulnerabilities affect Cisco Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of device configuration.
  • The Crosswork flaws include CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, each rated CVSS 10.0.
  • Cisco Secure Workload versions 3.10 and earlier are fixed in 3.10.9.1, and version 4.0 is fixed in 4.0.4.16.
  • Cisco said the vulnerabilities were found during internal testing and are not known to be actively exploited.
  • The update follows Cisco's resolution of 12 bugs in Catalyst SD-WAN and IOS XE Software about two weeks earlier.

Crosswork Platform Flaws

Four vulnerabilities affect Cisco Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of device configuration. CVE-2026-20030 is an SQL injection vulnerability with a CVSS score of 10.0. CVE-2026-20357 is a missing authentication for critical function vulnerability, also rated 10.0. CVE-2026-20358 is an external control of file system vulnerability with a CVSS score of 10.0. CVE-2026-20359 is an insufficiently protected credentials vulnerability rated 9.9. The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.

Secure Workload Fixes

Cisco released fixes for five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service and on-premises deployments. CVE-2026-20231 is a set of improper neutralization of special elements vulnerabilities spanning command, operating system, and argument injection, rated 9.9. CVE-2026-20315 is a set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses, rated 10.0. CVE-2026-20317 is a set of improper authentication vulnerabilities spanning missing authentication, authentication bypass, and reliance on untrusted inputs, rated 10.0. CVE-2026-20318 is a set of improper input validation vulnerabilities spanning input validation, path traversal, and external path control, rated 9.6. CVE-2026-20319 is a set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes, rated 7.5. The five vulnerabilities have been patched in Cisco Secure Workload Release 3.10.9.1 for versions 3.10 and earlier, and in 4.0.4.16 for version 4.0.

Security Review Context

Cisco said the vulnerabilities were found during internal testing and are not known to be actively exploited. The company urged customers to apply the necessary updates to avoid future exposure. The development comes about two weeks after Cisco resolved 12 bugs impacting Catalyst SD-WAN and IOS XE Software following the internal security review. The review has resulted in software hardening releases that address multiple internally discovered vulnerabilities, according to Cisco. Earlier this month, Cisco warned that a vulnerability impacting Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software, CVE-2026-20349 with CVSS score 8.6, has been exploited in the wild.

1 source

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0