Cisco Patches

Cisco Patches Nine Crosswork Flaws with CVSS 10.0 Ratings

Cisco has issued important updates for Crosswork platforms and Cisco Secure Workload after a fresh round of internal review. The most urgent findings include several flaws with CVSS scores at the top of the scale, making patching a priority for many teams. If you manage these products, you need to know which Cisco software releases are affected, what the risks look like, and which fixed versions close the gaps. These Cisco Patches are crucial, and that context starts with the flaw overview below.

Overview of Cisco’s Nine Crosswork and Secure Workload Flaws

Cisco disclosed four Crosswork flaws and five Cisco Secure Workload flaws as part of a broader hardening effort. The Secure Workload issues include improper access control, improper authentication, improper input validation, injection weaknesses, and memory safety problems.

Cisco’s security vulnerability information shows that the company used a CWE grouping approach, assigning one CVE ID to each underlying vulnerability class. This helps explain why each advisory covers multiple related weaknesses rather than a single narrow bug. The next sections break down the main categories and their severity.

Key Findings and Flaw Categories

Here’s the simple picture. Cisco found serious issues in both product lines, but the flaw types differ. Crosswork included high-risk infrastructure problems such as SQL injection and authentication gaps. Secure Workload centered on grouped weakness classes in one security advisory, making it easier to map each issue to an underlying vulnerability class.

Notable recent CVEs tied to Secure Workload include grouped entries that cover broad behavior patterns rather than one bug at a time. That means one CVE may represent several related validation or authorization problems.

  • CVE-2026-20231 covers injection-style weaknesses tied to improper neutralization of special elements.
  • CVE-2026-20315 covers improper access control across authorization, privileges, and bypasses.
  • CVE-2026-20317 covers improper authentication, including missing checks and bypass paths.
  • CVE-2026-20319 covers memory issues such as buffer overflows and out-of-bounds writes.

That structure gives you a clearer way to prioritize remediation by weakness family, not just by product name.

Severity Assessment and CVSS 10 Ratings

Severity is the part you cannot ignore. In Cisco Secure Workload, two grouped vulnerabilities received a CVSS score of 10.0, while the others ranged from 9.9 to 7.5. In Crosswork, three flaws also reached 10.0, with another rated 9.9. That tells you the attack surface includes issues with very high potential impact.

Cisco’s security advisory also points to an earlier May issue, CVE-2026-20223, a separate Cisco Secure Workload API flaw rated 10.0. It allowed unauthenticated Site Admin access through crafted internal API requests.

Product CVE ID CVSS Score Summary
Crosswork CVE-2026-20030 10.0 SQL injection
Crosswork CVE-2026-20357 10.0 Missing authentication for critical function
Crosswork CVE-2026-20358 10.0 External control of file system
Crosswork CVE-2026-20359 9.9 Insufficiently protected credentials
Cisco Secure Workload CVE-2026-20231 9.9 Injection-related weaknesses
Cisco Secure Workload CVE-2026-20315 10.0 Access control weaknesses
Cisco Secure Workload CVE-2026-20317 10.0 Authentication weaknesses
Cisco Secure Workload CVE-2026-20318 9.6 Input validation weaknesses
Cisco Secure Workload CVE-2026-20319 7.5 Memory buffer issues
Cisco Secure Workload CVE-2026-20223 10.0 Unauthorized API access

Impact of Secure Workload Flaws on Cross-Tenant Security

The biggest concern in Cisco Secure Workload is cross-tenant security. Cisco said one API weakness could let an unauthenticated attacker gain Site Admin privileges through crafted requests, even though the issue does not depend on device configuration.

With that level of access, an attacker could read sensitive information and make configuration changes across tenant boundaries. In shared environments, that creates a direct control-plane risk, not just a local product bug. To understand the exposure better, it helps to look at how this access path works in practice.

Understanding the Cross-Tenant Exposure Risk

Cross-tenant security matters because Secure Workload is used to enforce visibility and segmentation across workloads. If an attacker reaches Site Admin privileges, the exposure risk goes beyond one account or one tenant. They may gain visibility into shared environments and alter enforcement boundaries.

Cisco’s May advisory described this as an internal REST API issue. A crafted request to a vulnerable endpoint could bypass normal checks, even without prior authentication. That means low attack complexity if the attacker has network access to the affected endpoint.

The flaw was discovered during internal security testing, and Cisco said it was not known to be actively exploited. Even so, the impact is serious. A successful attacker could read protected data, modify policies, and affect tenant separation. For organizations using multi-tenant deployments, that is a strong reason to upgrade without delay.

Consequences for Organizations Using Cisco Crosswork

If your organization uses Cisco Crosswork, the immediate consequence is operational risk tied to severe flaws in management platforms. SQL injection, missing authentication, and file system control issues can create broad impact, especially when they affect core network tooling regardless of configuration.

The practical step is simple: move to the fixed versions and review Cisco guidance under its security vulnerability policy. Cisco repeatedly warns customers to patch to avoid future exposure because there are no complete workarounds in these advisories. Waiting increases your own risk, especially in products with high-value network access.

If you cannot obtain software through your normal channel, Cisco says you may need support through your point of sale or the Cisco Technical Assistance Center. That matters because delay is often the real problem. Even without known exploitation today, exposed management systems can become attractive targets very quickly.

Cisco’s Response and Patch Release Details

Cisco’s response has been structured and direct. Through Cisco PSIRT and each security advisory, the company said the flaws were discovered during internal testing and that it is not aware of malicious use or public announcements tied to these issues.

The patch releases are part of a broader hardening effort and reflect Cisco’s evolving disclosure cadence around risk and remediation. For customers asking whether Cisco has released critical patches for Secure Workload vulnerabilities, the answer is yes. The next two sections show when fixes appeared and how you can apply them.

Timeline of Vulnerability Discovery and Patch Deployment

Cisco said these flaws were found during internal testing, including existing testing processes and, in one advisory, frontier AI models. That language shows the findings came from a proactive search rather than from active incidents reported in the field.

The May 20-21, 2026 disclosure covered the critical Secure Workload unauthorized API access issue, CVE-2026-20223. Cisco released fixes for supported versions and stated that SaaS deployments had already been remediated at the infrastructure level. No workaround was offered.

Later, in August 2026, Cisco published another hardening release after a comprehensive internal security review. That disclosure process grouped multiple Secure Workload weaknesses by CWE class and also covered four Crosswork flaws. Together, the two advisories show a steady patch cycle aimed at reducing risk in core products before attackers can take advantage.

How to Access and Apply the Latest Cisco Patches

Start by checking your release against Cisco’s fixed software guidance. For the August hardening update, Secure Workload 3.10 and earlier is fixed in 3.10.9.1, while 4.0 is fixed in 4.0.4.16. For the May API flaw, 3.10 is fixed in 3.10.8.3 and 4.0 in 4.0.3.17, while 3.9 and earlier must move to a supported new release.

Cisco says customers can use its support and downloads resources to confirm entitlement and coverage. If you cannot get the package through standard channels, contact the Cisco Technical Assistance Center for help.

  • Review the affected release and match it to the fixed software release in the advisory.
  • Use the My Devices tool and support pages to check customer device support coverage.
  • Keep your product serial number ready if you need a free upgrade through Cisco support.
  • Upgrade Cluster, Agent, and Connector software where required to fully remediate Secure Workload issues.

Conclusion

In conclusion, addressing the nine CVSS 10.0 rated flaws in Cisco’s Crosswork and Secure Workload systems is crucial for maintaining robust security within your organization. With the increasing complexities of cyber threats, timely patching is essential to safeguard your data and infrastructure. Cisco’s proactive approach in identifying and rectifying these vulnerabilities underscores its commitment to ensuring secure operations for its users. Stay informed and vigilant by regularly checking for updates and applying patches as soon as they are available. If you have any concerns about how these flaws might affect your systems, don’t hesitate to reach out for assistance.

Frequently Asked Questions

How can I check if my Cisco Secure Workload deployment is affected by these flaws?

Check the release information in the Cisco advisory and compare it with your Cisco Secure Workload version. You can also use the My Devices tool to review support coverage. If you need help accessing updates, keep your product serial number ready for Cisco support.

What are the risks of not patching Secure Workload vulnerabilities promptly?

Delaying patches increases exposure risk, especially for flaws that can allow unauthorized access, configuration changes, or access to sensitive information. Cisco’s security vulnerability information makes clear that unsupported or unpatched systems face future exposure, even when no active exploitation is currently known.

Where can I find official Cisco security advisories about these flaws?

You can find official details in Cisco security advisories published by the Cisco product security incident response team. These advisories explain the disclosure process, affected Cisco software releases, fixed versions, and upgrade guidance for Secure Workload and related products.

TUNE IN
TECHTALK DETROIT