Skip to content
Beveiligingsnieuws

Cisco Crosswork Security Updates: Key CVEs Fixed

Cisco patches

Cisco has published a fresh set of security updates for its Crosswork platforms and Secure Workload Software following an ongoing internal security review. The releases target multiple vulnerabilities across different components, with several issues rated at the highest CVSS levels.

In this update, Cisco highlights fixes for problems affecting Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, along with additional patches for Cisco Secure Workload deployments (both SaaS and on-premises). Below is a practical overview of what was fixed, which versions are impacted, and where to apply the remediation.

What Cisco is fixing in Crosswork platforms

According to Cisco, four Crosswork-related vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of how the devices are configured. These flaws were identified as part of Cisco’s internal testing and are now addressed in specific software releases.

For administrators managing older installations, the key point is that Crosswork Release version 7.2.1 and earlier are affected. Cisco also indicates that the problems have been addressed in version 7.2.1-SP.

Crosswork CVEs and severity

Cisco lists the following Crosswork vulnerabilities:

  • CVE-2026-20030 (CVSS 10.0) — SQL injection vulnerability.
  • CVE-2026-20357 (CVSS 10.0) — missing authentication for a critical function.
  • CVE-2026-20358 (CVSS 10.0) — external control of file system vulnerability.
  • CVE-2026-20359 (CVSS 9.9) — insufficiently protected credentials vulnerability.

The combination of injection, authentication gaps, file system exposure, and credential protection weaknesses makes this Crosswork portion of the Cisco Crosswork security updates especially important for teams working with customer-facing or high-trust network orchestration systems.

Secure Workload patches: SaaS and on-prem

Alongside the Crosswork fixes, Cisco also released remediation for five vulnerabilities impacting Cisco Secure Workload Software. Cisco explicitly notes that the fixes apply to both Software-as-a-Service (SaaS) deployments and on-premises environments, which is helpful for organizations that operate hybrid architectures.

While the CVEs span a range of security categories—such as improper access control, authentication issues, and input validation problems—Cisco’s core message remains the same: apply the updates in the versions listed to reduce future exposure.

Secure Workload CVEs and what they involve

Cisco’s advisory lists these Secure Workload vulnerabilities:

  • CVE-2026-20231 (CVSS 9.9) — improper neutralization of special elements, including command, operating system, and argument injection.
  • CVE-2026-20315 (CVSS 10.0) — improper access control across authorization, authentication, privileges, and bypasses.
  • CVE-2026-20317 (CVSS 10.0) — improper authentication, covering missing authentication, authentication bypass, and reliance on untrusted inputs.
  • CVE-2026-20318 (CVSS 9.6) — improper input validation, including input validation failures, path traversal, and external path control.
  • CVE-2026-20319 (CVSS 7.5) — improper restriction of operations within memory buffer boundaries, including buffer overflows and out-of-bounds writes.

From an operational standpoint, this mix suggests multiple ways an attacker could potentially influence behavior, whether through bypassing authentication, manipulating authorization paths, or feeding crafted inputs that exploit validation gaps.

Which Secure Workload versions include the fixes

To help customers map their current deployments to the patched releases, Cisco identifies specific version targets for Secure Workload:

  • Secure Workload Release 3.10 and earlier — fixed in 3.10.9.1.
  • Secure Workload Release 4.0 — fixed in 4.0.4.16.

If you maintain an older build line, the important action is to move to the fixed point release listed by Cisco. For security teams, it’s also wise to confirm that both your update mechanism and your change management process can deploy these versions without breaking dependencies on surrounding systems.

No active exploitation reported for these issues

Cisco states that the vulnerabilities were discovered during internal testing and that there is no known active exploitation at the time of the announcement. Even so, the company urges customers to apply the necessary updates to avoid future exposure.

This is a common but crucial distinction: lack of observed exploitation does not mean an issue is harmless. Many high-severity flaws—especially those rated CVSS 9+—can become attractive once attackers identify working payloads or chain vulnerabilities together.

Why this update matters for enterprise networks

Network infrastructure is often a high-value target because it can provide visibility into traffic patterns and may allow attackers to pivot across segmented environments. Cisco notes that its equipment is widely used in enterprise networks, which makes it an appealing target for malicious actors.

In the past, Cisco products have repeatedly been leveraged in real-world compromise attempts involving unauthorized access and malware deployment. That history is a strong reminder that timely patching is part of maintaining a credible security posture.

Earlier Cisco hardening releases and the broader trend

This security update comes shortly after Cisco addressed additional issues related to Catalyst SD-WAN and IOS XE Software. Cisco describes its ongoing internal review as producing “software hardening releases” designed to address multiple internally discovered vulnerabilities.

For organizations, this pattern supports a simple operational takeaway: treat internal security review outputs as an ongoing cycle, not as a one-time event. Regularly review your vendor advisories, validate impacted versions, and schedule patch windows accordingly.

Context: Secure Firewall ASA/FTD vulnerability exploited in the wild

Beyond this Crosswork and Secure Workload announcement, Cisco also previously warned about a vulnerability affecting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. Cisco indicated that CVE-2026-20349 (CVSS 8.6) had been exploited in the wild.

While that earlier issue relates to a different product line, it reinforces why network teams should take Cisco Crosswork security updates seriously—even when a particular set of vulnerabilities has not been observed being exploited.

Recommended next steps

If you operate Crosswork or Secure Workload, the most effective response is straightforward:

  • Verify versions across Crosswork components and Secure Workload deployments.
  • Apply Cisco’s fixed releases (Crosswork 7.2.1-SP; Secure Workload 3.10.9.1 or 4.0.4.16 depending on your branch).
  • Document the change and validate service health after upgrade, especially where authentication and input handling are involved.
  • Monitor advisories from Cisco as internal security reviews continue to generate hardening releases.

By acting promptly on the Cisco Crosswork security updates, you reduce the likelihood that known classes of attack—such as SQL injection, authentication bypass, file system control, and injection through special elements—can be used against your environment.

Conclusion

Cisco’s latest security updates focus on high-severity vulnerabilities affecting Crosswork platforms and Secure Workload Software. Multiple Crosswork-related CVEs carry CVSS scores of 10.0, while Secure Workload patches address issues across authentication, access control, input validation, and memory buffer handling.

Even though Cisco reports no known active exploitation for this specific set of flaws, the company’s guidance is clear: update to the patched versions to prevent future attacks. If you manage these systems, start by confirming your current version and planning upgrades to the releases Cisco listed.

Source: https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html