Cisco corregge nove vulnerabilità critiche in Crosswork e Secure Workload
Vulnerabilities

Illustrative image generated with AI

Cisco Fixes Nine Critical Vulnerabilities in Crosswork and Secure Workload

Cisco fixes nine critical vulnerabilities in Crosswork and Secure Workload, with CVSS scores up to 10.0, requiring immediate updates. No workarounds available.

Text generated by artificial intelligence, published without human review. AI transparency

Two Advisories, Nine CVEs, and No Workarounds

Cisco has published two security advisories covering vulnerabilities in Cisco Crosswork and Cisco Secure Workload. The updates were published on August 19, 2026, and the Crosswork advisory was updated on August 21, 2026.

The flaws were discovered during internal security activities using the company’s established testing processes, as well as frontier artificial intelligence models. Cisco says it is not aware of active exploitation, public disclosure, or malicious use of the vulnerabilities.

The advisories group the issues by CWE category and assign a CVE to each group. There are nine identifiers in total: four affecting Crosswork and five affecting Secure Workload.

The overall material refers to six vulnerabilities with a CVSS score of 10.0. However, the individual advisory entries and available data explicitly list five CVEs rated 10.0: three in Crosswork and two in Secure Workload. The remaining scores are 9.9, 9.6, and 7.5.

Crosswork: SQL Injection, Missing Authentication, and Controllable File System Paths

The cisco-sa-hardening-crosswork-UzDTU9Vh advisory covers four products:

  • Cisco Crosswork Data Gateway
  • Cisco Crosswork Network Controller
  • Cisco Crosswork Planning
  • Cisco Crosswork Workflow Manager

The impact is configuration-independent. Revision 2.0 of the advisory officially added Workflow Manager to the list of affected products.

The vulnerable and fixed versions are:

  • Data Gateway, Network Controller, and Planning: version 7.2.1 and earlier, fixed in 7.2.1-SP;
  • Workflow Manager: version 2.1.1 and earlier, fixed in 2.1.1-SP.

The four vulnerabilities are:

  • CVE-2026-20030, CVSS 10.0, CWE-89: improper neutralization of special elements in SQL commands, resulting in SQL injection;
  • CVE-2026-20357, CVSS 10.0, CWE-306: a critical function can be accessed without authentication;
  • CVE-2026-20358, CVSS 10.0, CWE-73: external control of file system paths or resources;
  • CVE-2026-20359, CVSS 9.9, CWE-522: insufficient protection of credentials.

For the first three CVEs, the CVSS vectors indicate network-based attacks requiring low complexity, no prior privileges, and no user interaction. Potential impacts include loss of confidentiality, data modification, and service disruption.

CVE-2026-20359 requires low privileges. For CVE-2026-20358, the confidentiality impact is rated none, while the impacts on integrity and availability remain high.

Cisco has not published workarounds for these vulnerabilities.

Secure Workload Affects SaaS and On-Premises Deployments

The second advisory, cisco-sa-hardening-csw1-shSvndWP, covers Cisco Secure Workload Software in both Software as a Service and on-premises deployments. Here too, the impact is described as independent of device configuration.

The required fixes depend on the release branch:

  • 3.10 and earlier: upgrade to 3.10.9.1;
  • 4.0: upgrade to 4.0.4.16.

Five CVEs are affected:

  • CVE-2026-20231, CVSS 9.9, CWE-74: improper neutralization of special elements, potentially enabling command, OS, or argument injection;
  • CVE-2026-20315, CVSS 10.0, CWE-284: improper access control, including authorization, privilege, and bypass flaws;
  • CVE-2026-20317, CVSS 10.0, CWE-287: improper, missing, or bypassable authentication;
  • CVE-2026-20318, CVSS 9.6, CWE-20: improper input validation, path traversal, and external control of paths;
  • CVE-2026-20319, CVSS 7.5, CWE-119: operations that are not adequately restricted to buffer boundaries, potentially resulting in overflows and out-of-bounds writes.

Available CVSS data indicates that at least some of the most severe vulnerabilities can be exploited over the network without authentication or user interaction. Others require low privileges. Potential impacts include unauthorized access to or modification of resources, command execution, bypassing security controls, and loss of availability.

All Cluster, Agent, and Connector components must be updated to fully eliminate exposure. In SaaS deployments, Cisco has already updated the Cluster component; customers must therefore update Agent and Connector.

No workarounds are available for Secure Workload either.

What Administrators Should Do

Cisco’s recommended mitigation is to upgrade to the fixed versions. Before proceeding, administrators should verify available memory, hardware compatibility, and support for their current configurations.

The Crosswork upgrade plan is:

  • Data Gateway, Network Controller, and Planning to 7.2.1-SP;
  • Workflow Manager to 2.1.1-SP.

For Secure Workload, administrators must update:

  • all components in the 3.10 branch to 3.10.9.1;
  • all components in the 4.0 branch to 4.0.4.16.

Customers unable to obtain the packages through the usual purchasing channel should contact the Cisco Technical Assistance Center or their maintenance provider. Cisco asks customers to have the serial number and advisory URL available.

No indicators of compromise, specific detection rules, or dedicated forensic procedures have been provided. In the absence of workarounds, customers unable to update immediately should at least review management interface exposure, check for unusual access, and monitor unexpected attempts to reach services, paths, or administrative functions. These measures do not replace the required updates.

CISA KEV Status and Known Exploitation

The available NVD records do not list a CISA Known Exploited Vulnerabilities status for these CVEs. Consequently, there is no KEV inclusion date or CISA deadline available.

The absence of a KEV deadline does not reduce the technical severity of the flaws. The highest scores describe vulnerabilities that may be exploitable remotely, in some cases without authentication, but Cisco says it is not currently aware of active attacks or known malicious use.

There is insufficient information to determine whether Cisco has had other recent entries in the KEV catalog related to these products. At present, the confirmed operational facts are the lack of workarounds and the availability of the fixed releases listed in the advisories.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsCisco vulnerabilitiesCrossworkSecure WorkloadCVSS 10.0security updatesnetwork securityCVEcritical flaws
Back to home