AI analysis
CVE-2026-20358 is an external control of the file system vulnerability (CWE-73) in Cisco Crosswork that Cisco's Crosswork engineering team discovered during an internal security review and addressed in a software hardening release announced for publication on August 19, 2026. Per the CVSS vector, it is exploitable remotely over the network without authentication or user interaction, and an attacker's ability to influence the file names or paths the software uses lets it operate on files outside its intended security scope. An attacker gains the ability to modify or overwrite files and disrupt the platform, with the score rating integrity and availability impact as high and confidentiality impact as none; the specific vulnerable interface or protocol is not described in the available data. At risk are organizations running Cisco Crosswork, and the companion advisory batch from the same date also patched flaws in Cisco Secure Workload, though no affected or fixed version numbers were provided in the available data. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Upgrade Cisco Crosswork to the fixed release in Cisco's August 19, 2026 security advisory, checking the Cisco PSIRT advisory for the exact affected and fixed version ranges since they were not included in the available data. As an interim mitigation, restrict unauthenticated network access to Crosswork management interfaces, review the companion Cisco Secure Workload advisories from the same release, and monitor for a first published proof-of-concept or KEV addition.
Affected
| Cisco Crosswork | — |
| Cisco Secure Workload | — |
Estimated exposure
moderateapprox. a few thousand deployments worldwide (estimated 1k-10k systems) — No install counts appear in the provided data; Cisco Crosswork is a network-automation platform deployed primarily by large enterprises and service providers rather than at consumer scale, so exposure is estimated as thousands of…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE) CWE-73.