Cisco has released patches for nine vulnerabilities in two of its enterprise network management products, Crosswork and Secure Workload, with five of the flaws receiving the maximum possible severity score of 10.0 on the Common Vulnerability Scoring System. The company published the advisories on August 19, 2026, and they were reported in detail by The Hacker News and SecurityWeek shortly after.
Four of the vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller and Crosswork Planning, in versions 7.2.1 and earlier. CVE-2026-20030 is a SQL injection flaw, CVE-2026-20357 is caused by missing authentication for a function that should require it, and CVE-2026-20358 allows external control of file names or paths on the server. All three carry the top score of 10.0. A fourth issue, CVE-2026-20359, involves insufficiently protected credentials and scored 9.9. Cisco fixed all four in version 7.2.1-SP.
The remaining five vulnerabilities affect Secure Workload, the company’s micro-segmentation platform, in both its cloud-based and on-premises versions. CVE-2026-20315, an improper access control flaw, and CVE-2026-20317, an improper authentication flaw, both scored 10.0. CVE-2026-20231, a command and OS injection issue, scored 9.9. CVE-2026-20318, tied to path traversal from improper input validation, scored 9.6, and CVE-2026-20319, a buffer overflow and out-of-bounds write bug, scored 7.5. Cisco addressed these in Secure Workload versions 3.10.9.1 and 4.0.4.16.
Taken individually or combined, the highest-scoring flaws would let an attacker with no valid account and no prior access reach the affected system over the network and, depending on the specific bug, run arbitrary database queries, log in without a password, read or overwrite files, or pull stored credentials off the server. Because Crosswork and Secure Workload are typically used by large telecom operators and enterprises to monitor and manage their own network infrastructure, a successful attack against either product could hand an intruder visibility into, or a foothold inside, the surrounding network rather than just the management tool itself.
Cisco said it is not aware of any of the nine vulnerabilities being exploited in the wild, and no public proof-of-concept exploit code was available as of publication. The company also patched a separate, unrelated high-severity flaw in Cisco BroadWorks, CVE-2026-20320, an XML external entity injection bug scoring 7.5 that could let an unauthenticated remote attacker read sensitive configuration information. That fix shipped in version RI.2026.07.
There are no workarounds for any of the Crosswork or Secure Workload vulnerabilities, so Cisco is telling administrators to install the updated software directly. Organizations running either product on the affected versions should treat the upgrade as urgent given how many of the flaws require no authentication at all to exploit.
Source: The Hacker News, “Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0”, with additional detail from Cisco’s official security advisory notice.
