Two Advisories, One Day, Nine Flaws
Cisco published two separate security advisories on 19 August 2026, revealing nine vulnerabilities across two of its most sensitive product lines. The first advisory, 'Cisco Crosswork Security Hardening Release: August 2026', covers Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning and Crosswork Workflow Manager. The second, 'Cisco Secure Workload Software Security Hardening Release: August 2026', covers Cisco Secure Workload in both its SaaS and on-premises forms.
Crosswork is the platform telcos and large enterprise network operators use to automate their network fabric programmatically, while Secure Workload is a micro-segmentation and zero-trust product that enforces policy between workloads. Between them, the two advisories list four and five CVEs respectively, nine in total.
Cisco's own advisory states plainly that the company is 'not aware of any public announcements or malicious use of the vulnerabilities described in this advisory' for either disclosure. The Hacker News and SecurityWeek both covered the pair of advisories after Cisco published them.
Nine CVEs, Five Perfect Scores
The nine vulnerabilities span SQL injection, missing authentication, external control of the file system, improper access control, improper authentication, command injection, input validation flaws and a buffer overflow. Five of the nine reach the maximum possible CVSS score of 10.0, and a sixth sits at 9.9, an unusually dense cluster of near-maximum severity ratings for a single day of disclosures.
| Advisory | CVE | CVSS Score | Vulnerability Class |
|---|---|---|---|
| Crosswork | CVE-2026-20030 | 10.0 | SQL injection |
| Crosswork | CVE-2026-20357 | 10.0 | Missing authentication for a critical function |
| Crosswork | CVE-2026-20358 | 10.0 | External control of file system |
| Crosswork | CVE-2026-20359 | 9.9 | Insufficiently protected credentials |
| Secure Workload | CVE-2026-20231 | 9.9 | Command/OS/argument injection |
| Secure Workload | CVE-2026-20315 | 10.0 | Improper access control |
| Secure Workload | CVE-2026-20317 | 10.0 | Improper authentication |
| Secure Workload | CVE-2026-20318 | 9.6 | Input validation flaws |
| Secure Workload | CVE-2026-20319 | 7.5 | Buffer overflow |
Cisco lists a fixed version for every affected product: Crosswork Data Gateway, Crosswork Network Controller and Crosswork Planning all move to 7.2.1-SP, Crosswork Workflow Manager moves to 2.1.1-SP, and Secure Workload moves to 3.10.9.1 or 4.0.4.16 depending on the release track. Cisco states explicitly that no workaround exists for either advisory, so the fixed release is the only mitigation available.
The Control Plane Carries a Bigger Blast Radius
Crosswork and Secure Workload are not ordinary applications, they are the control plane that runs and secures the network around them. Crosswork automates the network fabric itself, and Secure Workload enforces the micro-segmentation and zero-trust boundaries between workloads, so a flaw in either tool carries a categorically larger blast radius than a flaw in a single endpoint or application.
An unauthenticated SQL injection or missing-authentication bug at CVSS 10.0 in Crosswork does not just expose the Crosswork server itself, it potentially reaches every device the platform is authorized to automate, because compromising the tool that controls everything else can compromise everything it controls. The same logic applies to Secure Workload, where a perfect-10 access control or authentication flaw in the product that enforces segmentation boundaries risks undoing the very isolation it was deployed to create.
This is the pattern operators should weigh above the individual CVE numbers. Orchestration and policy-enforcement software sits above the systems it manages, so its own security posture sets a ceiling on the security of everything beneath it.
Cisco Found These Flaws Before Anyone Else Did
Both advisories are the product of Cisco's own internal engineering security review, not a report from an outside researcher and not a response to active exploitation. Most disclosures in this space reach operators only after an external researcher or an attacker in the wild forces the vendor's hand.
Finding five perfect-10 vulnerabilities through internal review before any outsider does is genuinely proactive security work, and it deserves to be named as such. It also raises a fair question for operators about their own control-plane software: if one internal review at Cisco turned up nine flaws this severe in a single pass, other vendors' equivalent platforms have likely not had the same level of scrutiny yet.
The Patch Path for Both Advisories
Because neither advisory offers a workaround, the upgrade itself is the only real mitigation. Crosswork Data Gateway, Crosswork Network Controller and Crosswork Planning customers need version 7.2.1-SP, and Crosswork Workflow Manager customers need version 2.1.1-SP.
Secure Workload customers on Release 3.10 or earlier need 3.10.9.1, and those on Release 4.0 need 4.0.4.16. SaaS customers only need to update their Agent and Connector components, since Cisco manages the cluster itself, while on-premises customers must upgrade the Cluster, Agent and Connector together.
Not yet exploited describes today's status, and status can change. With no workaround available, scheduling the upgrade is the only action that actually closes the exposure.
Read next: The Cisco Bug Under Attack Scored Just 5.3 | An 18-Year-Old Cisco Bug Now Has a 3-Day Deadline



