AI analysis
CVE-2026-20357 describes missing authentication for critical functions (CWE-306) in Cisco Crosswork, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the flaw requires no privileges and is reachable over the network with low attack complexity, an unauthenticated remote attacker could invoke critical functionality directly. The CVSS 10.0 score, with scope change and high confidentiality, integrity, and availability impacts, indicates successful attacks could compromise the Crosswork platform and spill over to other components it manages. Organizations running Cisco Crosswork — typically large enterprises and service providers using it for network automation — are affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Review Cisco's August 19, 2026 Crosswork advisory for the affected version list and upgrade to the software hardening release it specifies, since version details are not included in this data. Until patched, restrict network access to Crosswork management interfaces and monitor Cisco PSIRT for updates. No workarounds or in-the-wild exploitation are documented at this time.
Estimated exposure
nichelikely hundreds to low thousands of enterprise/service-provider deployments (specialized platform; exact install base unknown) — Cisco Crosswork is a specialized network automation platform sold to large enterprises and service providers rather than mass-market software, and no public install counts or internet-exposure scan data were provided in the available data.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function issues that are grouped under the Common Weakness Enumeration (CWE) CWE-306.