All incidents

Cisco patches multiple critical vulnerabilities in Crosswork and Secure Workload

vulnerabilityopenAug 20, 2026 — Aug 21, 2026
Cisco patches critical flaws in Crosswork and Secure Workload

CISCO has issued patches for nine critical vulnerabilities affecting its Crosswork and Secure Workload platforms.

The move follows internal testing that uncovered six flaws rated at the maximum CVSS score of 10.0 according to its advisory here.

The most severe flaw, tracked as CVE-2026-20030, is a SQL injection bug in Crosswork that allows an unauthenticated attacker to manipulate database queries and carries a CVSS rating of 10.0 as detailed by researchers here.

Another tracked issue, CVE-2026-20320, affects BroadWorks with a CVSS score of 7.5 and relates to improper input handling.

Alongside the SQL injection, Cisco fixed four additional high‑risk issues in Crosswork, including missing authentication for critical functions and an improper input validation flaw.

In Secure Workload the advisories cover improper authentication and weak access control mechanisms, while the remaining bugs affect related components such as BroadWorks where CVE-2026-20320 received a CVSS score of 7.5.

Cisco said there is no evidence that any of these vulnerabilities have been exploited in the wild and no threat actors have been linked to the flaws.

However, the publication of details often draws rapid interest from attackers, so organisations are urged to treat the updates as urgent.

Administrators should verify the current versions of Crosswork and Secure Workload in their environments and apply the recommended releases listed in the Cisco advisory.

They should also review authentication settings, restrict database access to trusted hosts and monitor logs for unusual query patterns that could indicate attempted SQL injection.

It is wise to maintain an up‑to‑date inventory of all Cisco products, test patches in a staging window before broad rollout and subscribe to Cisco’s security notifications to stay ahead of future alerts.

Regularly checking for new advisories helps ensure that similar issues are addressed before they can be exploited.

Intelligence briefing updated Aug 21, 2026

CVE-2026-20030 10.0 CVE-2026-20320 7.5
Root sourcesec.cloudapps.cisco.com
Timeline Coverage

Swipe to explore timeline