Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Cisco Crosswork, Secure Workload CVEs Patched
Aug 24, 2026
4 Mins Read
Moon
Summarize with:

Cisco Crosswork, Secure Workload CVEs Patched

Cisco released security updates for Cisco Crosswork and Cisco Secure Workload, addressing nine vulnerabilities across the two product families.

The updates include five maximum severity issues involving SQL injection, missing authentication, file-control weaknesses, improper access control, and improper authentication. Other patched flaws involve credential protection, command injection, input validation, and memory handling.

Cisco says the vulnerabilities were found during internal security testing, including testing with frontier AI models, and that it is not aware of public announcements or malicious exploitation. Because Cisco lists no workarounds, affected deployments should be upgraded to the fixed releases.

Which Cisco Products Are Affected?

Product family Affected product/component Fixed release / action
Cisco Crosswork Data Gateway, Network Controller, Planning Upgrade to 7.2.1-SP
Cisco Crosswork Workflow Manager Upgrade to 2.1.1-SP
Cisco Secure Workload On-premises 3.10 and earlier Upgrade Cluster, Agent, and Connector to 3.10.9.1
Cisco Secure Workload On-premises 4.0 Upgrade Cluster, Agent, and Connector to 4.0.4.16
Cisco Secure Workload SaaS Agent and Connector Customers must update these components

Cisco has already upgraded the Secure Workload SaaS Cluster software. For Crosswork, Cisco added Workflow Manager to the advisory on August 21, 2026.

What Are the Five CVSS 10.0 Cisco Flaws?

CVE-2026-20030: SQL Injection in Cisco Crosswork

CVE-2026-20030 covers SQL injection issues in Cisco Crosswork, mapped to CWE-89. SQL injection flaws occur when application input is not properly separated from database commands, allowing crafted input to affect how a query is interpreted.

Details of CVE-2026-20030 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-20030 (SOCRadar Vulnerability Intelligence)

CVE-2026-20357: Missing Authentication in Cisco Crosswork

CVE-2026-20357 is a missing authentication issue in Cisco Crosswork, mapped to CWE-306. This type of flaw can allow access to a critical function without the authentication checks that should protect it. The risk is highest where Crosswork management interfaces are reachable from untrusted networks.

CVE-2026-20358: File Control Weakness in Cisco Crosswork

CVE-2026-20358 is an external file control issue in Cisco Crosswork, mapped to CWE-73. This weakness can occur when externally influenced input affects a file name or path used by the application. Depending on the affected operation, file-control flaws may lead to unintended file access, overwrite, or other unsafe file interaction.

CVE-2026-20315: Access Control Flaw in Secure Workload

CVE-2026-20315 affects Cisco Secure Workload and is mapped to CWE-284, improper access control. In security-management platforms, access control weaknesses can be serious because they may expose protected operations, policies, or administrative workflows.

The advisory applies to Secure Workload SaaS and on-premises deployments, regardless of configuration.

CVE-2026-20317: Authentication Flaw in Secure Workload

CVE-2026-20317 is an improper authentication issue in Cisco Secure Workload, mapped to CWE-287. Authentication flaws can undermine the checks that confirm whether a user, service, or component should be trusted.

Because Secure Workload supports workload-security visibility and policy operations, affected deployments should be upgraded quickly, especially where administrative access is broadly reachable.

How Can SOCRadar Help?

SOCRadar’s Cyber Threat Intelligence (CTI) module helps teams track Cisco CVEs, advisory changes, public PoC developments, exploit chatter, and threat activity around newly disclosed vulnerabilities.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

In parallel, SOCRadar’s Attack Surface Management (ASM) module helps identify externally reachable assets, exposed management services, DNS records, certificates, and vulnerable technologies, allowing defenders to prioritize internet-facing Crosswork and Secure Workload deployments during remediation.

Were Other Cisco CVEs Patched?

Yes. The same advisories also include CVE-2026-20359 in Crosswork, rated 9.9, and four Secure Workload CVEs: CVE-2026-20231 rated 9.9, CVE-2026-20318 rated 9.6, and CVE-2026-20319 rated 7.5. These should be remediated through the same fixed releases rather than handled separately.

Is There Active Exploitation?

Cisco PSIRT says it is not aware of public announcements or malicious use of the vulnerabilities described in the Crosswork and Secure Workload advisories. The advisories also do not provide public indicators of compromise, exploit payloads, or CVE-specific detection signatures.

What Should Defenders Do Now?

Inventory all Cisco Crosswork and Secure Workload deployments, then compare installed versions against Cisco’s fixed-release tables. Upgrade Crosswork Data Gateway, Network Controller, and Planning to 7.2.1-SP, and Crosswork Workflow Manager to 2.1.1-SP where applicable.

For Secure Workload, upgrade version 3.10 and earlier to 3.10.9.1, and version 4.0 to 4.0.4.16. Confirm that Cluster, Agent, and Connector components are all covered.

Because Cisco lists no workarounds, restrict management interfaces to trusted administrative networks while upgrades are planned. Review logs for unusual management activity, unexpected authentication failures, unknown service identities, anomalous API requests, SQL-related application errors, unexpected file access, new accounts, role changes, and unauthorized policy or connector modifications.