BlackTree Security · Infrastructure · Automation · AI

Five 10.0 Bugs, No Workaround: Cisco Hardens Crosswork and Secure Workload

Cisco has released two unusually broad security hardening updates for Crosswork and Secure Workload. Together, the advisories cover nine CVE groupings, five with a maximum CVSS score of 10.0, across systems that manage network orchestration and workload segmentation.

The immediate operational point is simple: there are no workarounds. Cisco says the flaws were found internally and it is not aware of malicious use or public announcements. That is reassuring, but it does not reduce the need to move affected installations onto the fixed software baselines.

Crosswork: four vulnerability classes across the control plane

The Crosswork advisory applies regardless of device configuration to Crosswork Data Gateway, Network Controller, Planning, and Workflow Manager. Cisco grouped multiple underlying findings by Common Weakness Enumeration class, so each CVE can represent more than one internal issue. The published score is the highest severity within that group.

  • CVE-2026-20030, CVSS 10.0: improper neutralisation of special elements in SQL commands.
  • CVE-2026-20357, CVSS 10.0: missing authentication for a critical function.
  • CVE-2026-20358, CVSS 10.0: external control of the file system.
  • CVE-2026-20359, CVSS 9.9: insufficiently protected credentials.

Crosswork Data Gateway, Network Controller, and Planning releases 7.2.1 and earlier must move to 7.2.1-SP. Workflow Manager 2.1.1 and earlier must move to 2.1.1-SP. Cisco updated the advisory on 21 August to add Workflow Manager as an affected product, which means inventories based only on the original release may be incomplete.

Secure Workload: the cluster is only part of the patch

The separate Secure Workload advisory covers both SaaS and on-premises deployments, again regardless of device configuration.

  • CVE-2026-20231, CVSS 9.9: special-element neutralisation failures covering command, operating-system, and argument injection.
  • CVE-2026-20315, CVSS 10.0: improper access control, including authorisation, authentication, privilege, and bypass issues.
  • CVE-2026-20317, CVSS 10.0: improper authentication, including missing authentication, authentication bypass, and reliance on untrusted inputs.
  • CVE-2026-20318, CVSS 9.6: improper input validation, including path traversal and external path control.
  • CVE-2026-20319, CVSS 7.5: memory-buffer boundary errors, including overflows and out-of-bounds writes.

Secure Workload 3.10 and earlier must be upgraded to 3.10.9.1. Version 4.0 must move to 4.0.4.16. For on-premises deployments, the Cluster, Agent, and Connector all need to be upgraded. Cisco has already upgraded the Cluster component for SaaS customers, but those customers still need to update their Agent and Connector software.

Five perfect scores do not mean five isolated bugs

The disclosure structure matters. Cisco did not assign one identifier to every underlying finding. It grouped findings by weakness class and attached a CVE and the highest applicable score to each class. Defenders should therefore treat the release as a product hardening baseline, not as a checklist of nine isolated code paths.

The affected products sit close to high-value trust boundaries: orchestration, data gateways, planning workflows, workload policy, agents, and connectors. Weakness classes such as missing authentication, access-control failure, SQL injection, command injection, path traversal, and file-system control can become especially consequential in those positions.

What defenders should do now

  • Inventory all four Crosswork products, including Workflow Manager, which Cisco added in the revised advisory.
  • Upgrade every affected Crosswork installation to the relevant service-pack release.
  • For Secure Workload, verify the Cluster, Agent, and Connector versions independently. A current cluster does not prove that the deployment is fully remediated.
  • Prioritise internet-reachable management interfaces and restrict administrative access while upgrades are staged.
  • Review authentication, administrative, file-access, and configuration-change telemetry for unexplained activity, while keeping the evidence distinction clear: Cisco has not reported active exploitation.

Cisco first published both advisories at 16:00 GMT on 19 August 2026. The Crosswork advisory was revised at 16:54 GMT on 21 August. Cisco says its engineering teams found the issues through existing internal testing processes and frontier AI models.

Leave a Reply

Your email address will not be published. Required fields are marked *