Full research report

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Original reporting โ†—
โ˜… Threat intelligence assessment medium confidence

Executive assessment

Cisco's August 2026 Crosswork and Secure Workload patch batch is the product of a continuing internal security review that has surfaced at least 21 high- and critical-severity vulnerabilities across Cisco's network-management and visibility portfolio within approximately a month. The concentration of CVSS 10.0 ratings reflects the privileged position these platforms occupy in enterprise networks: weaknesses such as missing authentication, SQL injection, and command injection on management interfaces carry maximum blast radius. Cisco's practice of grouping related sub-issues under single CVE identifiers suggests systemic input-handling deficiencies rather than isolated bugs, but it also limits defenders' ability to triage by specific component or exploitation condition. CVE-2026-20349 (ASA/FTD) is a distinct, earlier story โ€” a confirmed in-the-wild denial-of-service flaw against Cisco perimeter firewalls, now CISA KEV-listed โ€” which demonstrates that threat actors are actively probing Cisco's product estate and that unpatched Cisco infrastructure should be treated as high-priority regardless of formal exploitation confirmation on individual CVEs.

What happened

On 19 August 2026, Cisco's Product Security Incident Response Team published security hardening advisories for Crosswork platforms (Data Gateway, Network Controller, Planning) and Secure Workload, disclosing nine CVEs discovered during an ongoing internal security review. Five of the nine CVEs carry CVSS scores of 10.0, the maximum possible rating. Cisco states none of the nine vulnerabilities are known to be exploited at the time of publication. The release follows a similar internally generated patch batch for Catalyst SD-WAN and IOS XE approximately two weeks earlier.

Affected scope

Cisco Crosswork Release 7.2.1 and earlier (Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning), fixed in 7.2.1-SP, for CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359. Cisco Secure Workload Release 3.10 and earlier and Release 4.0, in both SaaS and on-premises deployments, fixed in 3.10.9.1 and 4.0.4.16 respectively, for CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, and CVE-2026-20319. All flaws apply regardless of device configuration.

Technical assessment

The Crosswork CVEs span SQL injection (CVE-2026-20030), missing authentication for a critical function (CVE-2026-20357), external file-system path control (CVE-2026-20358), and insufficiently protected credentials (CVE-2026-20359). The Secure Workload CVEs cover command and OS injection (CVE-2026-20231), improper access control and authorisation bypass (CVE-2026-20315), authentication bypass and reliance on untrusted inputs (CVE-2026-20317), path traversal and input validation failures (CVE-2026-20318), and memory-safety issues including buffer overflows and out-of-bounds writes (CVE-2026-20319). Cisco groups related sub-issues under single CVE identifiers, indicating clustered remediation of systemic input-handling weaknesses across management and data-plane interfaces rather than isolated individual bugs. The breadth of weakness classes and maximum severity ratings suggest core API or management-plane interfaces are affected.

Recommended defensive actions

  1. Apply Cisco Crosswork 7.2.1-SP immediately to address all four Crosswork CVEs (CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359).
  2. Upgrade Cisco Secure Workload to 3.10.9.1 (from 3.10 and earlier) or 4.0.4.16 (from 4.0) for all SaaS and on-premises deployments.
  3. Patch CVE-2026-20349 (Cisco ASA/FTD) if not already applied โ€” CISA required Federal Civilian Executive Branch agencies to remediate by 14 August 2026.
  4. Restrict management-plane and API access to Crosswork and Secure Workload interfaces to trusted network segments while patches are staged across environments.
  5. Subscribe to Cisco PSIRT advisories to track further hardening releases from the ongoing internal security review.

Uncertainties and evidence gaps

  • Cisco's practice of grouping multiple sub-issues under single CVE identifiers leaves the precise per-vulnerability attack surface, authentication requirements, and exploitability conditions insufficiently characterised in public advisories.
  • No independent technical analysis or researcher write-up has been published for any of the nine CVEs, making pre-authentication versus post-authentication exploitation conditions unverifiable from open sources.
  • The full scope and timeline of Cisco's ongoing internal security review has not been disclosed; further hardening releases may be pending.
  • Attribution for in-the-wild exploitation of the related CVE-2026-20349 (ASA/FTD) has not been publicly confirmed, so actor interest in the broader Cisco product estate remains unspecified.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessNetwork-accessible management or API interface; precise authentication requirement unconfirmed for highest-severity CVEs
ComponentCrosswork Data Gateway, Network Controller, and Planning management interfaces; Secure Workload API and application layer across SaaS and on-premises deployments
MechanismMultiple classes across both product lines: SQL injection, missing authentication on critical functions, external file-system path control, credential exposure, command and OS injection, authentication bypass, path traversal, and memory-safety violations
ImpactPotential for unauthenticated remote code execution, authentication bypass, credential disclosure, and data exfiltration across network management and workload-visibility platforms in enterprise environments
DetectionReview management-plane and API access logs for anomalous query patterns, unexpected authentication failures, unusual file-access requests, or elevated privilege usage against Crosswork and Secure Workload interfaces
MitigationApply Crosswork 7.2.1-SP and Secure Workload 3.10.9.1 / 4.0.4.16; no workarounds documented for the most severe CVEs
Exploitation status

The nine Crosswork and Secure Workload CVEs are not known to be actively exploited per Cisco's advisory; CVE-2026-20349, a separate Cisco ASA/FTD denial-of-service flaw cited in context, was previously confirmed exploited in the wild and added to the CISA KEV catalogue on 11 August 2026.

The investigation began with nine CVEs across Cisco Crosswork and Secure Workload, five rated CVSS 10.0, plus CVE-2026-20349 in the CISA KEV. Primary sources confirmed the Crosswork and Secure Workload patches were internally discovered with no known exploitation, while CVE-2026-20349 is a distinct ASA/FTD denial-of-service flaw with confirmed in-the-wild exploitation. Confidence is medium because individual per-CVE Cisco advisory pages could not be independently fetched, and the CISA KEV page returned HTTP 403, requiring reliance on secondary corroboration for that fact.

  1. What do the primary reporting outlet and the article text say about the nine CVEs, affected products, versions, and exploitation status?
    Fetched The Hacker News article on the Crosswork and Secure Workload patches
    thehackernews.com โ†—

    Nine CVEs confirmed across two product lines; Crosswork fixed in 7.2.1-SP, Secure Workload fixed in 3.10.9.1 and 4.0.4.16; Cisco states none are known to be actively exploited; CVE-2026-20349 referenced separately as a prior ASA/FTD issue now confirmed exploited.

    why Provided the baseline factual frame for the investigation but is secondary reporting requiring independent verification.

  2. Does Cisco's official PSIRT output confirm the advisory publication date, CVE groupings, and product scope?
    Searched for and fetched the Cisco advance notification page for August 2026 advisories
    sec.cloudapps.cisco.com โ†—

    Cisco PSIRT published the Crosswork and Secure Workload hardening advisories on 19 August 2026; the advance notification lists both advisory titles and their CVE groupings, confirming no exploitation at time of publication.

    why Primary Cisco source elevates confidence in the advisory date, CVE scope, and no-exploitation claim.

  3. Does an independent secondary source corroborate the CVE details, severity scores, and exploitation status?
    Fetched SecurityWeek's coverage of the Crosswork and Secure Workload patches
    securityweek.com โ†—

    SecurityWeek independently confirms all nine CVEs, CVSS scores, affected and fixed versions, and Cisco's statement of no known exploitation; also identifies a same-day BroadWorks advisory not part of this story.

    why Provides the independent corroboration from a second domain, consistent with primary reporting and Cisco's advisory.

  4. What are the confirmed exploitation details and CISA KEV context for CVE-2026-20349?
    Fetched The Hacker News article on CVE-2026-20349 ASA/FTD exploitation
    thehackernews.com โ†—

    CVE-2026-20349 (CVSS 8.6) is a denial-of-service vulnerability in Cisco ASA and FTD, exploitable unauthenticated via the Remote Access SSL VPN service; CISA added it to the KEV catalogue on 11 August 2026 with a Federal remediation deadline of 14 August 2026; no workaround is available.

    why Confirms and contextualises the CISA KEV entry from the source material, allowing clear separation of the unexploited Crosswork/Secure Workload CVEs from the actively exploited ASA/FTD flaw.

  5. Can the CISA KEV catalogue addition for CVE-2026-20349 be directly verified from a government source?
    Attempted to fetch the CISA KEV alert page
    cisa.gov โ†—

    The CISA page returned HTTP 403 Forbidden; content could not be retrieved. The KEV addition is confirmed by the source material (dated 2026-08-11) and corroborated by two independent secondary sources.

    why Direct government verification was unavailable; the KEV fact is treated as credible based on source material and secondary corroboration, with residual uncertainty noted.

TargetsEnterprise network operations centres using Cisco CrossworkOrganisations running Cisco Secure Workload (SaaS and on-premises)Organisations with Cisco ASA or FTD perimeter firewalls (CVE-2026-20349)

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 4 registered sources supplied useful evidence (2 primary, 1 corroborating, 1 contextual and 0 PoC/exploit references). 57 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful โ€” or not
CISA KEVkev ok1674 records Primary evidence1 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue.
The Hacker Newsnews ok7 records Primary evidence1 matched items Published the source report used to frame and date the event.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
FIRST EPSSepss ok7871 records Context1 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
BleepingComputernews ok9 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5332 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok686 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1009 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked โ€” no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok11 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok18 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok14 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok2 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Rapid7news ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 4 opened outside the registered collection
Vulnerability & exploitation2
CVE-2026-20349 CISA KEV Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) ยท added 2026-08-11 CISA catalog โ†—
CVE-2026-20349 EPSS 0.9% 56th percentile exploitation probability
Vendor & gov advisories1
Cisco Advance Notification for Publication of August 19, 2026, Security Advisories sec.cloudapps.cisco.com โ†—

Primary Cisco PSIRT source listing both Crosswork and Secure Workload hardening advisories published 19 August 2026.

Analysis & research3
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 thehackernews.com โ†—

Primary secondary reporting covering all nine CVEs with CVSS scores, affected versions, and fixed releases.

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities securityweek.com โ†—

Independent corroboration confirming CVSS scores, fixed versions, and no known exploitation across all nine CVEs.

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS thehackernews.com โ†—

Reporting on CVE-2026-20349 CISA KEV addition and confirmed exploitation of the ASA/FTD DoS flaw, providing context for the broader Cisco risk landscape.