Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Cisco patched 15 vulnerabilities across its product portfolio, with critical flaws in Crosswork and Secure Workload receiving CVSS scores of 10/10 Crosswork 7.2.1-SP addresses four critical CVEs involving SQL injection, missing authentication, external file system control, and insufficient credential protection Secure Workload versions 4.0.4.16 and 3.10.9.1 fix five CVEs including improper access control, command injection, path traversal, and buffer overflow issues A high-severity CVE-2026-2032
Analysis
TL;DR
- Cisco patched 15 vulnerabilities across its product portfolio, with critical flaws in Crosswork and Secure Workload receiving CVSS scores of 10/10
- Crosswork 7.2.1-SP addresses four critical CVEs involving SQL injection, missing authentication, external file system control, and insufficient credential protection
- Secure Workload versions 4.0.4.16 and 3.10.9.1 fix five CVEs including improper access control, command injection, path traversal, and buffer overflow issues
- A high-severity CVE-2026-20320 in BroadWorks' OCI XML parser allowed unauthenticated remote attackers to read sensitive configuration files via XXE attacks
- Cisco confirmed no known active exploitation in the wild but urged immediate patching across all affected products
Why It Matters
This release underscores the persistent risk of authentication bypass and injection vulnerabilities in enterprise networking and security platforms, which are prime targets for attackers seeking initial access to critical infrastructure. The concentration of CVSS 10.0 flaws in Cisco's own security and management products—Crosswork and Secure Workload—is particularly concerning for organizations that rely on these tools to protect their networks.
Technical Details
- Crosswork (v7.2.1-SP): Four critical CVEs patched—CVE-2026-20030 (SQL injection, CVSS 10), CVE-2026-20357 (missing authentication, CVSS 10), CVE-2026-20358 (external control of file system, CVSS 10), and CVE-2026-20359 (insufficient credential protection, CVSS 9.9). Exploitation could lead to RCE, authentication bypass, path traversal, and file overwrite/deletion.
- Secure Workload (v4.0.4.16 / v3.10.9.1): Five CVEs addressed, four rated critical—CVE-2026-20315 and CVE-2026-20317 (improper access control/authentication bypass), CVE-2026-20231 (code/OS command injection), CVE-2026-20318 (input validation/path traversal), and CVE-2026-20319 (buffer overflows/out-of-bounds writes).
- BroadWorks (RI.2026.07): CVE-2026-20320 (high severity) in the OCI XML parser allowed unauthenticated XXE attacks to read sensitive files with BroadWorks user privileges; resolved by disabling external entity resolution by default.
- Medium-severity patches also released for Unified Intelligence Center, RoomOS, Industrial Ethernet 1000 series switches, and Packaged/Unified Contact Center Enterprise.
Industry Insight
- Organizations running Cisco Crosswork or Secure Workload should prioritize immediate patching, as CVSS 10.0 authentication bypass and RCE flaws in security management platforms could give attackers full control over network defense infrastructure.
- The BroadWorks XXE vulnerability highlights the ongoing risk of legacy XML parsing configurations in telecom and enterprise platforms; default-deny approaches to external entity resolution should be standard practice.
- The pattern of grouped CVEs (multiple issues under a single vulnerability class) suggests systemic code-level weaknesses rather than isolated bugs, indicating that broader security audits of these product lines may be warranted beyond the disclosed patches.
Disclaimer: The above content is generated by AI and is for reference only.