Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

By The Hacker News
Publication Date: 2026-08-21 10:03:00

Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –

  • CVE-2026-20030 (CVSS score: 10.0) – An SQL injection vulnerability
  • CVE-2026-20357 (CVSS score: 10.0) – A missing authentication for critical function vulnerability
  • CVE-2026-20358 (CVSS score: 10.0) – An external control of file system vulnerability
  • CVE-2026-20359 (CVSS score: 9.9) – An insufficiently protected credentials vulnerability

The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.

Cybersecurity

Cisco has also released fixes to remediate five vulnerabilities affecting…