On Aug. 19, Cisco released coordinated security updates for two of its enterprise platforms: Cisco Crosswork and Cisco Secure Workload. The updates address nine CVE groupings, including five with a maximum CVSS score of 10.0. Two other groupings received scores of 9.9, while the remaining two were rated 9.6 and 7.5.
The vulnerabilities are tracked as CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359, CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318 and CVE-2026-20319. According to the company, they were identified during internal security tests using “existing testing processes” and “frontier AI models”.
The five maximum-severity groupings are CVE-2026-20030, involving SQL-injection weaknesses; CVE-2026-20357, relating to missing authentication for critical functions; CVE-2026-20358, involving external control of the file system; CVE-2026-20315, covering improper access controls; and CVE-2026-20317, concerning improper authentication.
The remaining groupings span command and argument injection, insufficiently protected credentials, input-validation and path-traversal weaknesses, and memory-buffer errors.
Cisco grouped the internally discovered vulnerabilities based on their underlying Common Weakness Enumeration classes. The score assigned to each CVE therefore represents the maximum potential severity of the most consequential underlying vulnerability within that category.
The approach forms part of a shift to scheduled, twice-monthly disclosures that Cisco has attributed to AI-accelerated vulnerability discovery outpacing traditional patch cycles.
Fixed releases, and one late addition
Cisco released separate security updates to patch flaws affecting Crosswork and Secure Workload, stating that there are no workarounds to address them.
The Crosswork vulnerabilities affect the platform’s Data Gateway, Network Controller, Planning tool and Workflow Manager, regardless of device configuration. To address them, users should update Data Gateway, Network Controller and Planning releases 7.2.1 and earlier to 7.2.1-SP, and update Workflow Manager 2.1.1 and earlier to 2.1.1-SP.
Cisco added Workflow Manager to the advisory on Aug. 21, two days after first publication. Customers who acted on the original version would not have seen it listed among the affected products.
The Secure Workload flaws affect SaaS and on-premises deployments, regardless of configuration. Customers should update Secure Workload 3.10 and earlier to 3.10.9.1, and version 4.0 to 4.0.4.16.
On-premises customers are advised to update their Cluster, Agent and Connector software. Cisco has already updated the Cluster component for SaaS deployments, but customers remain responsible for updating their Agents and Connectors.
Cisco’s Product Security Incident Response Team (PSIRT) was not aware of any public announcements or malicious exploitation when the security advisories were released.