Full Report
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below -
Analysis Summary
# Vulnerability: Cisco Crosswork and Secure Workload Critical Security Flaws
## CVE Details
- **CVE ID:** CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359, CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319
- **CVSS Score:** Range 7.5 to 10.0 (Critical/High)
- **CWE:** Multiple (SQLi, Missing Authentication, Path Traversal, Command Injection, Buffer Overflow)
## Affected Systems
- **Products:**
- Cisco Crosswork Data Gateway
- Cisco Crosswork Network Controller
- Cisco Crosswork Planning
- Cisco Secure Workload (SaaS and On-Premises)
- **Versions:**
- Crosswork: Release 7.2.1 and earlier
- Secure Workload: Release 3.10 and earlier; Release 4.0
- **Configurations:** Affects systems regardless of device configuration.
## Vulnerability Description
This suite of vulnerabilities stems from an internal security review and software hardening effort. The flaws include:
- **Crosswork Suite:** SQL injection (CVE-2026-20030), missing authentication for critical functions (CVE-2026-20357), unauthorized file system control (CVE-2026-20358), and unprotected credential storage (CVE-2026-20359).
- **Secure Workload:** Improper neutralization of special elements leading to OS command and argument injection (CVE-2026-20231); critical access control and authentication bypasses (CVE-2026-20315, CVE-2026-20317); path traversal and input validation issues (CVE-2026-20318); and memory safety issues including buffer overflows (CVE-2026-20319).
## Exploitation
- **Status:** Not exploited in the wild (discovered during internal testing).
- **Complexity:** Low (implied by CVSS 10.0 for several flaws).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** Total (Data exposure, credential theft).
- **Integrity:** Total (System compromise, file modification, command execution).
- **Availability:** Total (System takeover or crash).
## Remediation
### Patches
- **Cisco Crosswork:** Upgrade to version **7.2.1-SP**.
- **Cisco Secure Workload (3.10 and earlier):** Upgrade to version **3.10.9.1**.
- **Cisco Secure Workload (4.0):** Upgrade to version **4.0.4.16**.
### Workarounds
- No specific workarounds were provided in the advisory; Cisco recommends immediate software updates as the primary mitigation.
## Detection
- **Indicators of compromise:** Unusual administrative logins, unauthorized file system changes, or unexpected SQL queries in application logs.
- **Detection methods and tools:** Organizations should monitor network traffic for exploit patterns related to command injection and verify system integrity using Cisco’s internal auditing tools.
## References
- **Vendor Advisories:**
- hxxps://sec.cloudapps.cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh
- hxxps://sec.cloudapps.cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP
- **News Source:** hxxps://thehackernews[.]com/2026/08/cisco-patches-nine-crosswork-and-secure.html