CISCO has released security patches addressing nine critical vulnerabilities discovered during internal testing, including six rated with a maximum CVSS score of 10.0. These vulnerabilities impact various products within Cisco's Crosswork and Secure Workload software. Notably, four severe vulnerabilities in Crosswork include an SQL injection flaw and missing authentication for critical functions. In Secure Workload, vulnerabilities encompass improper authentication and access control.
Cisco affirmed that no active exploitation of these vulnerabilities has been detected. Companies using these products need to prioritize patching, as high CVSS scores tend to attract immediate attention once details are disclosed.