Cisco Patches Five Maximum-Severity Flaw Groupings

The flaws affect Crosswork and Secure Workload, with no available workarounds.

Published on Aug 24, 2026
Ingrid Fadelli Written by Ingrid Fadelli
CISO Live 2026

On Aug. 19, Cisco released coordinated security updates for two of its enterprise platforms: Cisco Crosswork and Cisco Secure Workload. The updates address nine CVE groupings, including five with a maximum CVSS score of 10.0. Two other groupings received scores of 9.9, while the remaining two were rated 9.6 and 7.5.

The vulnerabilities are tracked as CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359, CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318 and CVE-2026-20319. According to the company, they were identified during internal security tests using “existing testing processes” and “frontier AI models”.

The five maximum-severity groupings are CVE-2026-20030, involving SQL-injection weaknesses; CVE-2026-20357, relating to missing authentication for critical functions; CVE-2026-20358, involving external control of the file system; CVE-2026-20315, covering improper access controls; and CVE-2026-20317, concerning improper authentication.

The remaining groupings span command and argument injection, insufficiently protected credentials, input-validation and path-traversal weaknesses, and memory-buffer errors.

Cisco grouped the internally discovered vulnerabilities based on their underlying Common Weakness Enumeration classes. The score assigned to each CVE therefore represents the maximum potential severity of the most consequential underlying vulnerability within that category.

The approach forms part of a shift to scheduled, twice-monthly disclosures that Cisco has attributed to AI-accelerated vulnerability discovery outpacing traditional patch cycles.

Fixed releases, and one late addition

Cisco released separate security updates to patch flaws affecting Crosswork and Secure Workload, stating that there are no workarounds to address them.

The Crosswork vulnerabilities affect the platform’s Data Gateway, Network Controller, Planning tool and Workflow Manager, regardless of device configuration. To address them, users should update Data Gateway, Network Controller and Planning releases 7.2.1 and earlier to 7.2.1-SP, and update Workflow Manager 2.1.1 and earlier to 2.1.1-SP.

Cisco added Workflow Manager to the advisory on Aug. 21, two days after first publication. Customers who acted on the original version would not have seen it listed among the affected products.

The Secure Workload flaws affect SaaS and on-premises deployments, regardless of configuration. Customers should update Secure Workload 3.10 and earlier to 3.10.9.1, and version 4.0 to 4.0.4.16.

On-premises customers are advised to update their Cluster, Agent and Connector software. Cisco has already updated the Cluster component for SaaS deployments, but customers remain responsible for updating their Agents and Connectors.

Cisco’s Product Security Incident Response Team (PSIRT) was not aware of any public announcements or malicious exploitation when the security advisories were released.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Ingrid Fadelli
Ingrid Fadelli Contributing Reporter

Ingrid Fadelli is a freelance journalist with a BSc in Psychology and an MA in International Journalism, both from City University London. For the past 10 years, she has been writing articles focusing on research and emerging technologies in various fields, including AI, robotics, electronics engineering, cybersecurity, neuroscience, biology, physics and environmental science. She published articles in Phys.org, TechXplore, MedicalXpress, Scientia, E&T Magazine, and on various other media, translating complex scientific developments into engaging stories for broad audiences.