Security

Cisco Patches Five 10.0-Severity Flaws in Network Automation Tools

Emergency updates address critical authentication, SQL injection, and access control weaknesses in Crosswork and Secure Workload platforms.

Omega Editorial· August 23, 2026· 3 min read

Cisco released emergency security updates on August 19 addressing nine vulnerability classifications across its Crosswork network automation portfolio and Secure Workload security platform. Five of the disclosed weaknesses received the maximum possible CVSS severity score of 10.0, indicating critical risk to enterprise infrastructure.

The vulnerabilities affect systems that manage enterprise networks, orchestrate infrastructure, and enforce security policies across cloud and on-premises environments. Cisco identified the issues during internal security reviews and stated it was unaware of active exploitation at the time of disclosure. No workarounds exist—organizations must upgrade to patched versions.

Why it matters

These platforms occupy highly privileged positions within corporate and service-provider infrastructure. A successful compromise could expose sensitive network architecture data, undermine security policy enforcement, or enable lateral movement across managed systems. The vulnerabilities affect deployments regardless of configuration, meaning disabled features or custom setups provide no protection.

Understanding Cisco's CVE grouping approach

The nine published CVE identifiers do not represent nine isolated defects. Cisco grouped internally discovered weaknesses by their Common Weakness Enumeration categories and assigned one CVE per vulnerability class. Each severity score reflects the highest potential impact within that category.

This means a single CVE identifier can encompass multiple related security defects sharing a common technical cause. Security teams should recognize that vulnerability scanners reporting nine CVEs may understate the actual number of issues corrected in the updates.

Crosswork vulnerabilities threaten network automation

Four vulnerability categories affect Cisco Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning—tools used to automate IP transport networks, collect operational telemetry, and manage device configurations.

CVE-2026-20030 (CVSS 10.0) involves SQL injection weaknesses that could allow attackers to manipulate database queries and access infrastructure inventory, operational metadata, or configuration data.

CVE-2026-20357 (CVSS 10.0) exposes critical functions without proper authentication, potentially allowing network-accessible attacks requiring no privileges or user interaction.

CVE-2026-20358 (CVSS 10.0) permits external control of the file system, creating opportunities to read sensitive files, overwrite application data, or access resources outside intended directories.

CVE-2026-20359 (CVSS 9.9) involves insufficiently protected credentials that could enable attackers to move beyond the initially compromised system if obtained.

Affected Crosswork customers must upgrade to version 7.2.1-SP. Organizations should coordinate updates with infrastructure operations teams given the platform's role in network automation and service management.

Secure Workload flaws affect SaaS and on-premises deployments

Five vulnerability classifications affect Cisco Secure Workload, a platform designed for workload visibility, zero-trust microsegmentation, and policy enforcement. Both SaaS and on-premises deployments are vulnerable regardless of configuration.

CVE-2026-20315 (CVSS 10.0) covers improper access control that could expose operational information or allow unauthorized changes to security settings.

CVE-2026-20317 (CVSS 10.0) involves authentication failures that may allow unauthorized parties to reach protected functionality.

CVE-2026-20231 (CVSS 9.9) includes command injection weaknesses that could enable attackers to influence system commands.

CVE-2026-20318 (CVSS 9.6) encompasses path traversal issues that may permit access to configuration files, logs, certificates, or tokens.

CVE-2026-20319 (CVSS 7.5) covers memory safety weaknesses including buffer overflows.

Organizations using Secure Workload 3.10 or earlier should upgrade to version 3.10.9.1. Those using version 4.0 should upgrade to 4.0.4.16.

The Canadian Centre for Cyber Security issued an advisory urging administrators to review affected products and apply updates immediately.

These details were first reported by Automation Watch.

#cisco#network automation#vulnerability disclosure#crosswork#secure workload#critical patches

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

AI Agents Are Already Attacking Networks—Time to Use Them for Defense

Former CISA and NSA leaders say continuous AI-powered red teaming is now essential as attackers deploy autonomous bots that never sleep.

Via AI Watch · Aug 22, 2026
Security· 3 min read

Hugging Face Breach Shows AI's Double Role in Cybersecurity

An autonomous AI agent penetrated the platform's systems, while AI tools helped detect the intrusion—illustrating the technology's paradox for crisis management.

Via AI Watch · Aug 22, 2026
Security· 3 min read

Leading AI Labs Lack Public Plans to Contain Rogue Models

A new assessment finds most frontier AI companies have disclosed little about how they would respond if their systems tried to subvert human control.

Via AI Watch · Aug 22, 2026