ZeroHour
Product

Crosswork

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Six Maximum

Cisco patched nine critical flaws, six rated CVSS 10.0, in Crosswork platforms and Secure Workload, none known to be exploited.

Cisco released fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, discovered during an internal security review that used advanced AI models. Six flaws carry CVSS 10.0 ratings, including SQL injection CVE-2026-20030 and missing authentication CVE-2026-20357 in Crosswork, and access control CVE-2026-20315 and authentication flaws CVE-2026-20317 in Secure Workload. Fixes shipped in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16. Cisco says no exploitation has been observed.

Related CVEs

  • Unauthenticated SQL Injection (CWE-89) in Cisco Crosswork
    CVE-2026-20030 covers multiple SQL injection issues (CWE-89, improper neutralization of special elements used in SQL commands) in Cisco Crosswork, discovered by Cisco's own engineering team during a proactive internal security review and fixed in a dedicated software hardening release. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates an unauthenticated remote attacker could trigger the flaw by sending crafted input containing SQL special elements to a network-accessible component, with no user interaction required. The critical 10.0 score with scope changed (S:C) and high confidentiality, integrity, and availability impacts means a successful exploit could fully compromise the vulnerable component and potentially the wider system, allowing the attacker to run arbitrary SQL against the backing database, read or alter data, and disrupt service. Only organizations running Cisco Crosswork are affected by this CVE; the same August 19, 2026 advisory cycle also patched other Crosswork and Secure Workload flaws, five of which also scored CVSS 10.0. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days (44th percentile).
    · Cisco Crossworkniche
  • Missing Authentication for Critical Functions in Cisco Crosswork
    CVE-2026-20357 describes missing authentication for critical functions (CWE-306) in Cisco Crosswork, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the flaw requires no privileges and is reachable over the network with low attack complexity, an unauthenticated remote attacker could invoke critical functionality directly. The CVSS 10.0 score, with scope change and high confidentiality, integrity, and availability impacts, indicates successful attacks could compromise the Crosswork platform and spill over to other components it manages. Organizations running Cisco Crosswork — typically large enterprises and service providers using it for network automation — are affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
    · Cisco Crossworkniche
  • Improper Authentication Flaws in Cisco Secure Workload Score CVSS 10.0
    CVE-2026-20317 covers multiple improper authentication issues (CWE-287) in Cisco Secure Workload, discovered internally by Cisco's engineering team during a comprehensive security review and addressed in a software hardening release. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H) indicates the flaws are exploitable over the network by an unauthenticated attacker with no user interaction, and the changed scope means successful exploitation can affect components beyond the vulnerable one. An attacker could gain high-impact modification of system state and denial of service across the deployment, though the vector indicates no direct confidentiality (data disclosure) impact. Users of Cisco Secure Workload are affected; the fix was published as part of Cisco's August 19, 2026 advisory batch, which reportedly patched nine Crosswork and Secure Workload flaws, five of which scored CVSS 10.0. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days (37th percentile).
    · Cisco Secure Workloadniche
  • Unauthenticated External File-System Control in Cisco Crosswork (CVSS 10.0)
    CVE-2026-20358 is an external control of the file system vulnerability (CWE-73) in Cisco Crosswork that Cisco's Crosswork engineering team discovered during an internal security review and addressed in a software hardening release announced for publication on August 19, 2026. Per the CVSS vector, it is exploitable remotely over the network without authentication or user interaction, and an attacker's ability to influence the file names or paths the software uses lets it operate on files outside its intended security scope. An attacker gains the ability to modify or overwrite files and disrupt the platform, with the score rating integrity and availability impact as high and confidentiality impact as none; the specific vulnerable interface or protocol is not described in the available data. At risk are organizations running Cisco Crosswork, and the companion advisory batch from the same date also patched flaws in Cisco Secure Workload, though no affected or fixed version numbers were provided in the available data. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
    · Cisco Crosswork · Cisco Secure Workloadmoderate
  • Unauthenticated Improper Access Control in Cisco Secure Workload
    CVE-2026-20315 covers improper access control weaknesses (CWE-284) in Cisco Secure Workload that were found by Cisco's own engineering team during an internal security review and fixed in a dedicated software hardening release. Per the CVSS 10.0 vector, the flaws are exploitable remotely by unauthenticated attackers with no user interaction or special conditions required. Because the scope is changed with high confidentiality, integrity, and availability impact, a successful attacker could bypass access restrictions and gain broad, potentially full control over affected Secure Workload components and their data. Any organization running Cisco Secure Workload is affected; the fix ships as part of Cisco's August 19, 2026 advisory batch, which also patched Crosswork flaws, five of which scored the maximum CVSS 10.0. There is no known exploitation, no public proof-of-concept, and no KEV listing, and EPSS estimates only a 0.4% chance of exploitation within the next 30 days.
    · Cisco Secure Workloadniche
  • Insufficiently Protected Credentials in Cisco Crosswork
    CVE-2026-20359 is an insufficiently protected credentials flaw (CWE-522) in Cisco Crosswork, discovered by Cisco's own Crosswork engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the CVSS vector shows the issue is network-exploitable (AV:N) with low attack complexity and only low privileges required (PR:L), an attacker with limited access to the system could obtain or abuse credentials that are not adequately protected, gaining access that could affect confidentiality, integrity, and availability beyond the vulnerable component itself (scope changed, high impact across C/I/A). Affected organizations are those running Cisco Crosswork deployments, which are typically operated by service providers and large enterprises for network automation and management. As of now there is no evidence of exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS assigning only a 0.4% probability of exploitation in the next 30 days. The flaw was disclosed as part of a batch of nine internally discovered Crosswork and Secure Workload vulnerabilities published around Cisco's August 19, 2026 advisory release.
    · Cisco Crosswork (platform software)niche
  • Injection vulnerabilities (CWE-74) in Cisco Secure Workload
    CVE-2026-20231 bundles multiple injection-class vulnerabilities (CWE-74, improper neutralization of special elements) in Cisco Secure Workload, found by Cisco's own engineers during an internal security review and addressed in a software hardening release published alongside Cisco's August 19, 2026 advisories. The flaws are triggered remotely over the network by an authenticated, low-privileged user who submits input containing special elements that an affected component fails to neutralize. The CVSS 9.9 (critical) score, with a changed scope and high ratings for confidentiality, integrity, and availability, indicates a successful attack could compromise the vulnerable component and potentially extend to other components within the deployment. Only organizations running Cisco Secure Workload (formerly Tetration) are affected, and because valid low-privilege credentials and network access to the product's interfaces are required, exposure is concentrated in enterprise data-center environments. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists; EPSS currently estimates only a 0.5% chance of exploitation within 30 days.
    · Cisco Secure Workload (formerly Tetration)large
  • Improper Input Validation Bugs in Cisco Secure Workload (CVSS 9.6)
    Cisco has published a software hardening release for Cisco Secure Workload, its microsegmentation and workload-protection platform, fixing multiple internally discovered improper input validation vulnerabilities tracked as CVE-2026-20318 (CWE-20). An attacker with low-privileged (authenticated) access could send crafted input over the network, and because the software fails to properly validate it, could gain high-integrity control over data or configuration and disrupt availability of the affected component without any user interaction. The changed-scope metric in the CVSS vector (S:C) indicates the impact can extend beyond the vulnerable component's own security scope, though confidentiality is not listed as affected. Customers running Cisco Secure Workload are affected; related reporting notes the same August 19, 2026 advisory batch also patched Cisco Crosswork issues, but this CVE is scoped to Secure Workload. No public proof of concept or in-the-wild exploitation is known; the flaws came from Cisco's internal security review, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.
    · Cisco Secure Workloadmoderate
  • Buffer Management Flaws in Cisco Secure Workload Allow Remote Denial of Service
    CVE-2026-20319 describes a set of buffer management weaknesses (CWE-119) in Cisco Secure Workload, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. According to the CVSS vector, the flaws are remotely triggerable by unauthenticated attackers over the network, with low attack complexity and no user interaction required. The impact is to availability only: an attacker can cause a denial of service (high availability impact) with no effect on confidentiality or integrity. Organizations running Cisco Secure Workload are affected and should consult the Cisco advisory for the affected-release and fixed-release details. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.4% probability of exploitation within 30 days; it was published as part of Cisco's August 19, 2026 advisory batch, which also covered related Crosswork and Secure Workload flaws, though this particular issue scores 7.5 rather than the CVSS 10.0s in that release.
    · Cisco Secure Workloadmoderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.