Cisco Patches Five 10.0-Severity Flaws in Network Automation Tools
Emergency updates address critical authentication, SQL injection, and access control weaknesses in Crosswork and Secure Workload platforms.

Cisco released emergency security updates on August 19 addressing nine vulnerability classifications across its Crosswork network automation portfolio and Secure Workload security platform. Five of the disclosed weaknesses received the maximum possible CVSS severity score of 10.0, indicating critical risk to enterprise infrastructure.
The vulnerabilities affect systems that manage enterprise networks, orchestrate infrastructure, and enforce security policies across cloud and on-premises environments. Cisco identified the issues during internal security reviews and stated it was unaware of active exploitation at the time of disclosure. No workarounds exist—organizations must upgrade to patched versions.
Why it matters
These platforms occupy highly privileged positions within corporate and service-provider infrastructure. A successful compromise could expose sensitive network architecture data, undermine security policy enforcement, or enable lateral movement across managed systems. The vulnerabilities affect deployments regardless of configuration, meaning disabled features or custom setups provide no protection.
Understanding Cisco's CVE grouping approach
The nine published CVE identifiers do not represent nine isolated defects. Cisco grouped internally discovered weaknesses by their Common Weakness Enumeration categories and assigned one CVE per vulnerability class. Each severity score reflects the highest potential impact within that category.
This means a single CVE identifier can encompass multiple related security defects sharing a common technical cause. Security teams should recognize that vulnerability scanners reporting nine CVEs may understate the actual number of issues corrected in the updates.
Crosswork vulnerabilities threaten network automation
Four vulnerability categories affect Cisco Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning—tools used to automate IP transport networks, collect operational telemetry, and manage device configurations.
CVE-2026-20030 (CVSS 10.0) involves SQL injection weaknesses that could allow attackers to manipulate database queries and access infrastructure inventory, operational metadata, or configuration data.
CVE-2026-20357 (CVSS 10.0) exposes critical functions without proper authentication, potentially allowing network-accessible attacks requiring no privileges or user interaction.
CVE-2026-20358 (CVSS 10.0) permits external control of the file system, creating opportunities to read sensitive files, overwrite application data, or access resources outside intended directories.
CVE-2026-20359 (CVSS 9.9) involves insufficiently protected credentials that could enable attackers to move beyond the initially compromised system if obtained.
Affected Crosswork customers must upgrade to version 7.2.1-SP. Organizations should coordinate updates with infrastructure operations teams given the platform's role in network automation and service management.
Secure Workload flaws affect SaaS and on-premises deployments
Five vulnerability classifications affect Cisco Secure Workload, a platform designed for workload visibility, zero-trust microsegmentation, and policy enforcement. Both SaaS and on-premises deployments are vulnerable regardless of configuration.
CVE-2026-20315 (CVSS 10.0) covers improper access control that could expose operational information or allow unauthorized changes to security settings.
CVE-2026-20317 (CVSS 10.0) involves authentication failures that may allow unauthorized parties to reach protected functionality.
CVE-2026-20231 (CVSS 9.9) includes command injection weaknesses that could enable attackers to influence system commands.
CVE-2026-20318 (CVSS 9.6) encompasses path traversal issues that may permit access to configuration files, logs, certificates, or tokens.
CVE-2026-20319 (CVSS 7.5) covers memory safety weaknesses including buffer overflows.
Organizations using Secure Workload 3.10 or earlier should upgrade to version 3.10.9.1. Those using version 4.0 should upgrade to 4.0.4.16.
The Canadian Centre for Cyber Security issued an advisory urging administrators to review affected products and apply updates immediately.
These details were first reported by Automation Watch.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call
