ZeroHour

CVE-2026-20359

niche

Insufficiently Protected Credentials in Cisco Crosswork

CVSS 3.1
9.9 critical
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-20359 is an insufficiently protected credentials flaw (CWE-522) in Cisco Crosswork, discovered by Cisco's own Crosswork engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the CVSS vector shows the issue is network-exploitable (AV:N) with low attack complexity and only low privileges required (PR:L), an attacker with limited access to the system could obtain or abuse credentials that are not adequately protected, gaining access that could affect confidentiality, integrity, and availability beyond the vulnerable component itself (scope changed, high impact across C/I/A). Affected organizations are those running Cisco Crosswork deployments, which are typically operated by service providers and large enterprises for network automation and management. As of now there is no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS assigning only a 0.4% probability of exploitation in the next 30 days. The flaw was disclosed as part of a batch of nine internally discovered Crosswork and Secure Workload vulnerabilities published around Cisco's August 19, 2026 advisory release.

What to do: Check Cisco's August 19, 2026 Crosswork security advisories and upgrade affected Crosswork deployments to the software hardening release that addresses CVE-2026-20359. Until patching, restrict network access to the Crosswork management interfaces, limit low-privileged accounts, and rotate credentials that could be exposed through the platform. Since disclosure is part of a larger batch of nine Crosswork and Secure Workload fixes (five at CVSS 10.0), review all related advisories rather than this CVE alone.

Affected
Cisco Crosswork (platform software)
Estimated exposure
nichelikely on the order of thousands of deployments worldwide (estimate; no public install-base figures available) — Crosswork is a specialized network automation/management platform sold to service providers and large enterprises and deployed as per-organization management clusters rather than at internet-consumer scale, so exposure is limited to that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.

Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

Six Maximum

Cisco patched nine critical flaws, six rated CVSS 10.0, in Crosswork platforms and Secure Workload, none known to be exploited.

Cisco released fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, discovered during an internal security review that used advanced AI models. Six flaws carry CVSS 10.0 ratings, including SQL injection CVE-2026-20030 and missing authentication CVE-2026-20357 in Crosswork, and access control CVE-2026-20315 and authentication flaws CVE-2026-20317 in Secure Workload. Fixes shipped in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16. Cisco says no exploitation has been observed.

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0, found internally with no exploitation observed.

Cisco released fixes for four Crosswork platform vulnerabilities including CVE-2026-20030 SQL injection and CVE-2026-20357 missing authentication, both scoring CVSS 10.0, affecting Crosswork Release 7.2.1 and earlier. Five additional flaws in Secure Workload, including CVE-2026-20315 and CVE-2026-20317 at CVSS 10.0, affect SaaS and on-premises deployments up to releases 3.10 and 4.0. All issues were found through internal testing and are not known to be actively exploited. The patches follow a broader internal security review that recently addressed 12 Catalyst SD-WAN and IOS XE bugs.

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.

Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.