Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Cisco released patches for multiple critical vulnerabilities affecting its Crosswork and Secure Workload products, as well as other components like BroadWorks. These vulnerabilities include remote code execution, authentication bypass, path traversal, SQL injection, and buffer overflow issues. The flaws could allow attackers to execute arbitrary code, bypass authentication controls, and manipulate files. Cisco has issued fixes in Crosswork version 7.2.1-SP, Secure Workload versions 4.0.4.16 and 3.10.9.1, and BroadWorks version RI.2026.07. Cisco is not aware of any exploitation in the wild at this time.
AI Analysis
Technical Summary
Cisco announced patches addressing 15 vulnerabilities across multiple products, including critical and high-severity issues in Crosswork and Secure Workload. Crosswork 7.2.1-SP fixes four critical CVEs (CVE-2026-20030, CVE-2026-20357, CVE-2026-20358 with CVSS 10.0, and CVE-2026-20359 with CVSS 9.9) involving SQL injection, missing authentication, external control of file system, and insufficient credential protection. These could lead to remote code execution, authentication bypass, path traversal, and file manipulation. Secure Workload versions 4.0.4.16 and 3.10.9.1 address five CVEs including improper access control, authentication bypass, code/OS command injection, input validation, path traversal, buffer overflow, and out-of-bounds write issues. Additionally, BroadWorks RI.2026.07 fixes a high-severity XML parser flaw (CVE-2026-20320) allowing unauthenticated remote reading of sensitive configuration via external entity resolution. Other medium-severity vulnerabilities were patched in Unified Intelligence Center, RoomOS, IE 1000 switches, and contact center products. Cisco reports no known exploitation in the wild.
Potential Impact
Successful exploitation of these vulnerabilities could allow remote attackers to execute arbitrary code, bypass authentication mechanisms, perform path traversal and file overwrite or deletion, and read sensitive configuration data without authentication. This could lead to full system compromise, unauthorized access, and data exposure in affected Cisco products.
Mitigation Recommendations
Cisco has released official patches for all identified vulnerabilities in Crosswork (7.2.1-SP), Secure Workload (4.0.4.16 and 3.10.9.1), and BroadWorks (RI.2026.07). Users should apply these updates promptly. Cisco is not aware of any active exploitation, and no additional mitigation beyond patching is indicated by the vendor advisory.
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Description
Cisco released patches for multiple critical vulnerabilities affecting its Crosswork and Secure Workload products, as well as other components like BroadWorks. These vulnerabilities include remote code execution, authentication bypass, path traversal, SQL injection, and buffer overflow issues. The flaws could allow attackers to execute arbitrary code, bypass authentication controls, and manipulate files. Cisco has issued fixes in Crosswork version 7.2.1-SP, Secure Workload versions 4.0.4.16 and 3.10.9.1, and BroadWorks version RI.2026.07. Cisco is not aware of any exploitation in the wild at this time.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cisco announced patches addressing 15 vulnerabilities across multiple products, including critical and high-severity issues in Crosswork and Secure Workload. Crosswork 7.2.1-SP fixes four critical CVEs (CVE-2026-20030, CVE-2026-20357, CVE-2026-20358 with CVSS 10.0, and CVE-2026-20359 with CVSS 9.9) involving SQL injection, missing authentication, external control of file system, and insufficient credential protection. These could lead to remote code execution, authentication bypass, path traversal, and file manipulation. Secure Workload versions 4.0.4.16 and 3.10.9.1 address five CVEs including improper access control, authentication bypass, code/OS command injection, input validation, path traversal, buffer overflow, and out-of-bounds write issues. Additionally, BroadWorks RI.2026.07 fixes a high-severity XML parser flaw (CVE-2026-20320) allowing unauthenticated remote reading of sensitive configuration via external entity resolution. Other medium-severity vulnerabilities were patched in Unified Intelligence Center, RoomOS, IE 1000 switches, and contact center products. Cisco reports no known exploitation in the wild.
Potential Impact
Successful exploitation of these vulnerabilities could allow remote attackers to execute arbitrary code, bypass authentication mechanisms, perform path traversal and file overwrite or deletion, and read sensitive configuration data without authentication. This could lead to full system compromise, unauthorized access, and data exposure in affected Cisco products.
Mitigation Recommendations
Cisco has released official patches for all identified vulnerabilities in Crosswork (7.2.1-SP), Secure Workload (4.0.4.16 and 3.10.9.1), and BroadWorks (RI.2026.07). Users should apply these updates promptly. Cisco is not aware of any active exploitation, and no additional mitigation beyond patching is indicated by the vendor advisory.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/cisco-patches-critical-crosswork-secure-workload-vulnerabilities/","fetched":true,"fetchedAt":"2026-08-20T11:52:14.487Z","wordCount":1066}
Threat ID: 6a86ea6eacd9273b498fe1e4
Added to database: 08/20/2026, 11:52:14 UTC
Last enriched: 08/20/2026, 11:52:27 UTC
Last updated: 08/20/2026, 12:16:53 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.