CiberLATAMbywhalemate

Cisco patches nine Crosswork flaws

Cisco released hardening updates for Crosswork and Secure Workload that fix nine flaws, five rated CVSS 10.0, with no known workarounds.

Whalemate Labs · AI-assisted researchPublished:2 min read

Cisco published hardening releases in August 2026 for Cisco Crosswork and Cisco Secure Workload that address nine vulnerabilities, five of them rated CVSS 10.0. Among the flaws are CVE-2026-20030, a SQL injection issue in Crosswork Planning, and CVE-2026-20315, an improper access control problem in Secure Workload. In both cases, Cisco said there are no workarounds and that remediation requires updating to the specified versions.

Cisco published August 2026 hardening releases for Cisco Crosswork and Cisco Secure Workload that fix nine grouped vulnerabilities, five of them rated CVSS 10.0. Among the most significant are CVE-2026-20030, a SQL injection issue in Crosswork Planning, and CVE-2026-20315, an improper access control flaw in Secure Workload, both without known workarounds and requiring updates to specific versions.

What did Cisco fix in these products?

Cisco bundled several internally discovered issues into two security hardening packages, one for Crosswork and another for Secure Workload. In Crosswork, the available material indicates that the advisory covers nine vulnerabilities in total, while Secure Workload included CVE-2026-20315 along with other maximum-severity fixes.

The Hacker News reported that five of the nine vulnerabilities reached CVSS 10.0 and that the set spans SQL injection, missing authentication, improper access control, path traversal, and other security flaws. Secure-ISS, for its part, said Cisco patched four critical vulnerabilities in Secure Workload, all rated CVSS 10.0.

What is known about CVE-2026-20030?

CVE-2026-20030 is a critical SQL injection vulnerability in Cisco Crosswork Planning, with a CVSS v3.1 base score of 10.0, that allows an unauthenticated attacker to execute arbitrary SQL commands and potentially compromise the system. Ionix places it in versions 7.0.0 through 7.2.0, including 7.2.1 and earlier.

Cisco identified 7.2.1-SP or later as the first fixed release, and according to Ionix there are no workarounds for this flaw. The recommended mitigation is to update Cisco Crosswork Planning to version 7.2.1-SP or later. Feedly CVE also classifies it as SQL injection, with the ability to read, modify, or delete data, as well as compromise the system. OpenCVE adds that the associated EPSS remains below 1%, although the risk is still critical.

What was reported about CVE-2026-20315?

CVE-2026-20315 is a critical improper access control flaw in Cisco Secure Workload, with the maximum CVSS score of 10.0 and CWE-284 classification. Cisco published it in its security hardening release on August 19, 2026, and said it was identified internally during a security review.

Ionix said it affects SaaS and on-premises deployments and that no workarounds exist. The only remediation is to update to Secure Workload 3.10.9.1 for the 3.10 branch and 4.0.4.16 for the 4.0 branch. NVD also classifies it as a set of improper access control issues with critical severity.

Which versions are affected?

The Canadian Centre for Cyber Security issued advisory AV26-834 and warned that the vulnerabilities fixed by Cisco affect Crosswork Planning, in versions earlier than 7.2.1-SP, and Secure Workload 3.10, before 3.10.9.1, and 4.0, before 4.0.4.16. Its main recommendation was to update to those minimum versions.

The same agency clarified that the affected products are Cisco Crosswork Planning and Cisco Secure Workload, without limiting the impact to any particular deployment type. That means on-premises environments and other modes must also apply the specified versions. OpenCVE also said Cisco's advisory groups CVE-2026-20030 in a hardening release and that any deployment should be considered potentially vulnerable until the fix is applied.

QCS Studio also described the Crosswork hardening release as a package that includes a SQL command injection vulnerability tied to CVE-2026-20030. VCSolutions and HackerFeeds echoed that Cisco patched nine vulnerabilities in Crosswork and Secure Workload, with five cases marked CVSS 10.0, while CCBalert warned on X about eight critical issues with CVSS ranges between 10 and 9.6.

Sources

View all