Six Maximum
Cisco patched nine critical flaws, six rated CVSS 10.0, in Crosswork platforms and Secure Workload, none known to be exploited.
Cisco released fixes for nine critical vulnerabilities in its Crosswork platforms and Secure Workload software, discovered during an internal security review that used advanced AI models. Six flaws carry CVSS 10.0 ratings, including SQL injection CVE-2026-20030 and missing authentication CVE-2026-20357 in Crosswork, and access control CVE-2026-20315 and authentication flaws CVE-2026-20317 in Secure Workload. Fixes shipped in Crosswork 7.2.1-SP, Secure Workload 3.10.9.1, and 4.0.4.16. Cisco says no exploitation has been observed.
- Nine critical flaws patched across Crosswork and Secure Workload
- Six flaws rated maximum CVSS 10.0, including SQL injection
- Discovered via internal testing, reportedly using advanced AI models
- No known exploitation; fixed in 7.2.1-SP, 3.10.9.1, and 4.0.4.16
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20357 | Missing Authentication for Critical Functions in Cisco Crosswork CVE-2026-20357 describes missing authentication for critical functions (CWE-306) in Cisco Crosswork, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the flaw requires no privileges and is reachable over the network with low attack complexity, an unauthenticated remote attacker could invoke critical functionality directly. The CVSS 10.0 score, with scope change and high confidentiality, integrity, and availability impacts, indicates successful attacks could compromise the Crosswork platform and spill over to other components it manages. Organizations running Cisco Crosswork — typically large enterprises and service providers using it for network automation — are affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days. Do: Review Cisco's August 19, 2026 Crosswork advisory for the affected version list and upgrade to the software hardening release it specifies, since version details are not included in this data. Until patched, restrict network access to Crosswork management interfaces and monitor Cisco PSIRT for updates. No workarounds or in-the-wild exploitation are documented at this time. | 10.0 group max | <1% |
| nichelikely hundreds to low thousands of enterprise/service-provider deployments (specialized platform; exact install base unknown) | ||
| CVE-2026-20317 | Improper Authentication Flaws in Cisco Secure Workload Score CVSS 10.0 CVE-2026-20317 covers multiple improper authentication issues (CWE-287) in Cisco Secure Workload, discovered internally by Cisco's engineering team during a comprehensive security review and addressed in a software hardening release. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H) indicates the flaws are exploitable over the network by an unauthenticated attacker with no user interaction, and the changed scope means successful exploitation can affect components beyond the vulnerable one. An attacker could gain high-impact modification of system state and denial of service across the deployment, though the vector indicates no direct confidentiality (data disclosure) impact. Users of Cisco Secure Workload are affected; the fix was published as part of Cisco's August 19, 2026 advisory batch, which reportedly patched nine Crosswork and Secure Workload flaws, five of which scored CVSS 10.0. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days (37th percentile). Do: Review the Cisco Secure Workload security advisory (published August 19, 2026) for the exact affected and fixed release list, and upgrade to the corresponding software hardening release. Until patched, restrict network access to Secure Workload management and authentication interfaces to trusted administrative networks, since the flaw requires no authentication or user interaction. Given the CVSS 10.0 rating despite low current exploitation likelihood (EPSS 0.4%, no known PoC), prioritize patching within normal critical-vulnerability maintenance cycles. | 10.0 group max | <1% |
| nichelow thousands of enterprise deployments, with management/auth interfaces typically not internet-exposed |
Full article657 words · extracted from securityaffairs.com · click to collapse

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited.
Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.
“As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.” reads the advisory. “These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class – Common Weakness Enumeration (CWE) – and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.”
Four vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, all impacting these products regardless of how they’re configured:
- CVE-2026-20030 (CVSS score: 10.0) – an SQL injection vulnerability that lets an attacker manipulate database queries directly.
- CVE-2026-20357 (CVSS score: 10.0) – a missing authentication for critical function vulnerability, meaning a sensitive operation can be triggered without ever proving who you are.
- CVE-2026-20358 (CVSS score: 10.0) – an external control of file system vulnerability, letting an outside actor influence which files the system reads or writes.
- CVE-2026-20359 (CVSS score: 9.9) – an insufficiently protected credentials vulnerability, where stored login material isn’t locked down the way it should be.
Seeing three CVSS 10.0 vulnerabilities in a single Cisco advisory is unusual. The four flaws affect Crosswork 7.2.1 and earlier, and Cisco fixed them in version 7.2.1-SP.
Five more vulnerabilities got patched in Cisco Secure Workload, spanning both its cloud SaaS and on-premises deployments:
- CVE-2026-20231 (CVSS score: 9.9) – a set of improper neutralization of special elements vulnerabilities covering command, operating system, and argument injection, essentially several different ways to smuggle unintended commands into the system.
- CVE-2026-20315 (CVSS score: 10.0) – a set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses, a broad category that generally means the system doesn’t reliably enforce who’s allowed to do what.
- CVE-2026-20317 (CVSS score: 10.0) – a set of improper authentication vulnerabilities covering missing authentication, authentication bypass, and reliance on untrusted inputs, another maximum-severity cluster centered on identity verification failing outright.
- CVE-2026-20318 (CVSS score: 9.6) – a set of improper input validation vulnerabilities spanning input validation, path traversal, and external path control, the kind of flaw that lets crafted input reach files or directories it was never meant to touch.
- CVE-2026-20319 (CVSS score: 7.5) – a set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes, lower severity than the rest but still a genuine memory-safety problem.
The networking giant addressed five vulnerabilities in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
The company found these vulnerabilities during internal testing; it is not aware of attacks in the wild exploiting this issue.
“The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.” conctinues the advisory. “Cisco says it found the vulnerabilities through internal security testing that also used advanced AI models.”
Nobody’s reported active attacks against any of these nine flaws yet, and Cisco’s own review process caught them before an outside researcher or attacker did.
If your organization runs Crosswork or Secure Workload in any configuration, this isn’t a patch to schedule for next month’s maintenance window. Perfect CVSS scores tend to attract attention fast once a vulnerability’s technical details start circulating, and Cisco’s internal discovery only buys you a head start if you actually use it.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Cisco)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197640/security/six-maximum-severity-flaws-found-in-cisco-products.html