Cisco Rolls Out Critical Security Patches for Crosswork and Secure Workload Platforms
Cisco has released a new wave of security updates addressing several high-severity vulnerabilities across its Crosswork platforms and Secure Workload Software. These patches, stemming from an ongoing internal security review, target flaws including SQL injection, improper access control, and authentication bypasses, which could lead to significant compromise if left unaddressed.

**Cisco** has once again bolstered its security posture by issuing a fresh set of updates for its **Crosswork** platforms and **Secure Workload Software**. This initiative is part of a broader, continuous internal security review aimed at identifying and mitigating potential vulnerabilities.
### Critical Flaws in Crosswork Platforms
Four significant security vulnerabilities have been identified in **Cisco Crosswork Data Gateway**, **Cisco Crosswork Network Controller**, and **Cisco Crosswork Planning**. These flaws are present regardless of the device configuration:
* **CVE-2026-20030** (CVSS score: 10.0) - An SQL injection vulnerability.
* **CVE-2026-20357** (CVSS score: 10.0) - A missing authentication for critical function vulnerability.
* **CVE-2026-20358** (CVSS score: 10.0) - An external control of file system vulnerability.
* **CVE-2026-20359** (CVSS score: 9.9) - An insufficiently protected credentials vulnerability.
These issues impact **Cisco Crosswork Release** version 7.2.1 and earlier, with patches now available in version 7.2.1-SP.
### Remediation for Secure Workload Software
**Cisco** has also released fixes for five vulnerabilities affecting **Cisco Secure Workload**, covering both Software-as-a-Service (SaaS) and on-premises deployments:
* **CVE-2026-20231** (CVSS score: 9.9) - A set of improper neutralization of special elements vulnerabilities, including command, operating system, and argument injection.
* **CVE-2026-20315** (CVSS score: 10.0) - A set of improper access control vulnerabilities, spanning authorization, authentication, privileges, and bypasses.
* **CVE-2026-20317** (CVSS score: 10.0) - A set of improper authentication vulnerabilities, encompassing missing authentication, authentication bypass, and reliance on untrusted inputs.
* **CVE-2026-20318** (CVSS score: 9.6) - A set of improper input validation vulnerabilities, including path traversal and external path control.
* **CVE-2026-20319** (CVSS score: 7.5) - A set of improper restriction of operations within memory buffer vulnerabilities, such as buffer overflows and out-of-bounds writes.
These vulnerabilities have been patched in **Cisco Secure Workload Release** version 3.10.9.1 (for version 3.10 and earlier) and version 4.0.4.16 (for version 4.0).
### Proactive Measures and Known Exploits
**Cisco** emphasized that these vulnerabilities were discovered through internal testing and are not known to be actively exploited in the wild. Customers are strongly urged to apply the necessary updates promptly to mitigate potential exposure.
This latest round of updates follows closely on the heels of **Cisco**'s previous resolution of 12 bugs impacting **Catalyst SD-WAN** and **IOS XE Software**. The networking giant's proactive internal security review continues to yield software hardening releases, addressing multiple internally discovered flaws.
### The Allure of Cisco for Adversaries
The pervasive use of **Cisco** equipment within enterprise networks makes it a prime target for malicious actors. Threat groups have historically exploited numerous flaws in **Cisco** products to gain unauthorized access and deploy malware.
Earlier this month, **Cisco** issued a warning regarding active exploitation of a vulnerability impacting **Secure Firewall Adaptive Security Appliance (ASA) Software** and **Secure Firewall Threat Defense (FTD) Software** (**CVE-2026-20349**, CVSS score: 8.6), underscoring the critical importance of timely patching and robust security practices.