Protect.Computer
NEWS

Cisco Patches Nine Critical Flaws, Five Rated CVSS 10.0

· 1 min read · Network safety
Cisco Patches Nine Critical Flaws, Five Rated CVSS 10.0

Cisco has released patches addressing nine critical security vulnerabilities across two of its enterprise network management platforms: Crosswork (Data Gateway, Network Controller, and Planning) and Secure Workload (formerly Tetration). Five of the nine flaws carry a CVSS score of 10.0 — the maximum possible — meaning they can be exploited by unauthenticated attackers with no user interaction required.

The Crosswork flaws (CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359) include an SQL injection vulnerability, missing authentication on critical functions, and external control of the file system. The Secure Workload vulnerabilities (CVE-2026-20231, CVE-2026-20315, CVE-2026-20317, CVE-2026-20318, CVE-2026-20319) include authentication bypasses, command injection, and path traversal bugs affecting both SaaS and on-premises deployments. Cisco says none of the vulnerabilities are currently being exploited in the wild, and all were found during internal testing.

How to check if you’re affected

Affected versions are Crosswork 7.2.1 and earlier (fixed in 7.2.1-SP) and Secure Workload versions before 3.10.9.1 (3.10 line) and before 4.0.4.16 (4.0 line). If your organization runs either of these products, upgrade immediately using Cisco’s linked advisories below.

Sources

Related reading