Skip to content

Security3 publishers3 min readPublished Updated

Cisco's control planes are the exposure: four criticals in Crosswork, four in Secure Workload

Three of the Crosswork flaws score a flat 10.0, and Cisco says each CVE bundles several underlying defects. No exploitation reported in the wild so far.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Cisco announced patches on Wednesday for 15 vulnerabilities across its products, including critical- and high-severity flaws in Crosswork and Secure Workload.
  • Crosswork version 7.2.1-SP was released with fixes for four critical-severity CVEs.
  • CVE-2026-20030, CVE-2026-20357 and CVE-2026-20358 have a maximum severity rating, a CVSS score of 10/10.
  • CVE-2026-20359 has a CVSS score of 9.9/10.
  • According to Cisco, each CVE groups multiple issues under the same underlying vulnerability class.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Cisco released patches on Wednesday for 15 vulnerabilities across its portfolio, including critical- and high-severity flaws in Crosswork and Secure Workload [1]. The products carrying the worst of it are not edge devices or endpoints but the platforms that sit above production and tell it what to do.

Crosswork 7.2.1-SP fixes four critical CVEs [2]. Three of them, CVE-2026-20030, CVE-2026-20357 and CVE-2026-20358, carry a CVSS score of 10 out of 10 [3]; the fourth, CVE-2026-20359, is rated 9.9 [4]. The first three cover SQL injection, missing authentication, and external control of the file system, while the fourth includes insufficient protection of credentials [6]. Cisco says successful exploitation could allow remote code execution, authentication bypass, path traversal, and file overwrite or deletion [7]. That is the full set on a network automation platform, and the credential-protection item in the mix means the thing an attacker would go looking for is stored where the other three bugs reach.

Secure Workload 4.0.4.16 and 3.10.9.1 fix five CVEs, four of them rated critical [8]. CVE-2026-20315 and CVE-2026-20317 cover improper access control and authentication bugs that could lead to bypasses [9]; CVE-2026-20231 groups code and OS command injection [10]; CVE-2026-20318 covers input validation and path traversal [11]. The fifth, CVE-2026-20319, covers buffer overflows and out-of-bounds writes [12].

One detail is worth more than the scores. According to Cisco, each of these CVE identifiers groups multiple issues under the same underlying vulnerability class [5]. So the CVE count is a taxonomy decision, not a defect count, and anyone reconciling this against an internal patch ticket should assume the remediation surface inside each identifier is larger than one bug. Across the two platforms that is eight critical-rated identifiers to absorb in a single cycle [1].

Separately, Cisco fixed a high-severity flaw in the Open Client Interface XML parser in BroadWorks, CVE-2026-20320, exploitable remotely without authentication to read sensitive configuration information [13]. The cause was mundane: external entity resolution was allowed by default, so crafted XML messages could be used to view files with BroadWorks user privileges [14]. Fixes landed in version RI.2026.07 of the BroadWorks Application Delivery Platform, Application Server, Profile Server and Xtended Services Platform [15]. The remaining fixes are medium-severity issues in Unified Intelligence Center, RoomOS, the Industrial Ethernet 1000 series switches, and Packaged and Unified Contact Center Enterprise [16]. If Cisco's count of 15 maps one to one with the named CVEs, that leaves five spread across those four product lines [2].

Cisco says it is not aware of any of these vulnerabilities being exploited in the wild [17].

What to watch: whether the Crosswork and Secure Workload advisories draw exploitation activity, given that a 10.0 with missing authentication on an orchestration platform is the kind of target that gets reverse-engineered from the patch diff. Also watch how your own asset inventory treats these systems. Management and segmentation-policy platforms are frequently exempted from the maintenance windows applied to the infrastructure they govern, which is exactly the wrong way round this week.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories