Cisco has released a new round of security updates for its Cisco Crosswork and Secure Workload platforms , addressing a total of nine critical vulnerabilities , five of which are rated CVSS 10.0 — the highest possible severity rating. The vulnerabilities were discovered as part of an extensive internal security review conducted by the company, and there is no evidence of active exploitation online. However, their severity requires immediate application of available patches.

The issues affect three key components of the Crosswork platform : the Crosswork Data Gateway , the Crosswork Network Controller , and the Crosswork Planning . According to Cisco, the vulnerabilities affect devices regardless of their configuration, which significantly expands the circle of exposed systems. The affected versions are Crosswork Release 7.2.1 and earlier, while the fix is provided through version 7.2.1-SP .
The significance of these vulnerabilities cannot be underestimated. Cisco Crosswork are widely used in enterprise networks to automate and manage network infrastructure. A successful exploitation could give an attacker complete control of critical network functions, with devastating consequences for service integrity and availability.
See also: Critical vulnerability in Cisco Secure Workload – Update immediately
Cisco Crosswork: Analysis of the four critical vulnerabilities
The four vulnerabilities affecting Cisco Crosswork are particularly concerning due to their nature. CVE-2026-20030 (CVSS: 10.0) concerns an SQL injection, which could allow an attacker to gain access to databases, extract sensitive data, or even modify critical information. CVE-2026-20357 (CVSS: 10.0) concerns a lack of authentication for critical operations, allowing an attacker with network access to perform critical operations without credentials or user interaction.
CVE -2026-20358 (CVSS: 10.0) concerns external file system control, while CVE-2026-20359 (CVSS: 9.9) is related to poorly protected credentials. All four vulnerabilities require network access to exploit, and Cisco notes that there are no workarounds available for the Crosswork — the only solution is to upgrade to version 7.2.1-SP immediately.
Technically, the missing authentication is particularly dangerous in corporate network environments, as it allows an attacker who already has access to the network to perform administrative functions without having to bypass authentication mechanisms. This means that even an insider threat actor or an attacker who has already gained access to a portion of the network can escalate their privileges dramatically.
Cisco Secure Workload: Five additional critical vulnerabilities
Cisco also released fixes for five vulnerabilities affecting Cisco Secure Workload , both in SaaS deployments and on-premises environments. CVE-2026-20231 (CVSS: 9.9 ) concerns improper special-element deactivation, covering command injection , OS injection , and argument injection vulnerabilities . CVE-2026-20315 (CVSS: 10.0 ) concerns improper access control, including authorization, authentication, privileges, and override issues.

CVE -2026-20317 (CVSS: 10.0) concerns improper authentication, including no authentication, authentication bypass, and relying on untrusted inputs. CVE-2026-20318 (CVSS: 9.6) concerns improper input validation, covering path traversal and external path checking vulnerabilities. Finally, CVE-2026-20319 (CVSS: 7.5) concerns improper restriction of operations within memory buffer boundaries, including buffer overflow and out-of-bounds writes. The affected versions of Secure Workload are 3.10 before 3.10.9.1 and 4.0 before 4.0.4.16.
See also: CVE-2026-20251: RCE in Splunk Secure Gateway (CVSS 8.8) – what to do now
The variety of vulnerability types in Cisco Secure Workload — from injection attacks to buffer overflows — suggests that Cisco's internal security review was extremely thorough. The fact that these vulnerabilities were identified internally, before any external disclosure or exploitation, is a positive sign for the company's security process.
Cisco Crosswork and the broader cybersecurity framework
This announcement comes about two weeks after the company resolved 12 vulnerabilities affecting Catalyst SD-WAN and IOS XE Software, also as part of the same internal security review. Cisco has characterized this process as “software hardening releases that address multiple internally discovered vulnerabilities.” This suggests a systematic approach to product security that, while overdue, is particularly necessary given the widespread use of Cisco equipment in enterprise networks worldwide.
The prevalence of Cisco in corporate networks makes it an attractive target for malicious actors. This month, Cisco warned that a vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software — CVE-2026-20349 (CVSS: 8.6) — has already been actively exploited online. This highlights the risk that organizations face if they delay applying security updates for Cisco products.
Practical recommendations for protecting against Cisco Crosswork vulnerabilities
For organizations using the affected products, the recommendations are clear and urgent. First, Cisco Crosswork to version 7.2.1-SP immediately, as there are no workarounds. For Cisco Secure Workload, organizations should upgrade to versions 3.10.9.1 or 4.0.4.16 , depending on the release line they are using.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Cisco ASA and FTD: Active exploitation of CVE-2026-20349 in VPN

Second, it is critical to restrict network access to Cisco Crosswork and Secure Workload to trusted management nodes and management segments only. Since vulnerabilities require network access to exploit, proper network segmentation can significantly reduce the risk of exposure, even if the upgrade is delayed for business continuity reasons.
Third, security teams should actively monitor for unusual authentication attempts, unexpected administrative actions, and database activity consistent with SQL injection or unauthorized function calls. If patching is delayed, affected systems should be isolated from the wider corporate network and any management interfaces should be monitored for exposure. Cisco urges customers to apply the necessary updates as soon as possible to avoid future exposure.
