Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

The Hacker News by The Hacker News
August 21, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –

  • CVE-2026-20030 (CVSS score: 10.0) – An SQL injection vulnerability
  • CVE-2026-20357 (CVSS score: 10.0) – A missing authentication for critical function vulnerability
  • CVE-2026-20358 (CVSS score: 10.0) – An external control of file system vulnerability
  • CVE-2026-20359 (CVSS score: 9.9) – An insufficiently protected credentials vulnerability

The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.

Cisco has also released fixes to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) and on-premises deployments –

  • CVE-2026-20231 (CVSS score: 9.9) – A set of improper neutralization of special elements vulnerabilities spanning command, operating system, and argument injection
  • CVE-2026-20315 (CVSS score: 10.0) – A set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses
  • CVE-2026-20317 (CVSS score: 10.0) – A set of improper authentication vulnerabilities spanning missing authentication, authentication bypass, and reliance on untrusted inputs
  • CVE-2026-20318 (CVSS score: 9.6) – A set of improper input validation vulnerabilities spanning input validation, path traversal, and external path control
  • CVE-2026-20319 (CVSS score: 7.5) – A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes

The five vulnerabilities have been patched in the versions below –

  • Cisco Secure Workload Release version 3.10 and earlier – Fixed in 3.10.9.1
  • Cisco Secure Workload Release version 4.0 – Fixed in 4.0.4.16

“These vulnerabilities were found during internal testing and are not known to be actively exploited,” the company said, urging customers to apply the necessary updates to avoid future exposure.

The development comes about two weeks after Cisco resolved 12 bugs impacting Catalyst SD-WAN and IOS XE Software following the internal security review. The review, the networking equipment major added, has “resulted in software hardening releases that address multiple internally discovered vulnerabilities.”

The prevalence of Cisco gear within enterprise networks makes it an attractive target for bad actors, who have repeatedly exploited dozens of flaws impacting its products to gain unauthorized access and deploy malware.

Earlier this month, Cisco warned that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.



Source link

The Hacker News

The Hacker News

Next Post

Only 1 in 5 organizations are prepared to move toward autonomous AI agents, Deloitte finds

Recommended.

Start small, win big: How to choose the right AI use cases

Start small, win big: How to choose the right AI use cases

June 16, 2025
Kyndryl Launches Agentic AI Framework To Combine Business AI, Human Capabilities

Kyndryl Launches Agentic AI Framework To Combine Business AI, Human Capabilities

July 21, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio