Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
PatchCrossworkSecure WorkloadOur summary
Cisco has issued security updates to address 15 vulnerabilities, highlighting critical defects in its Crosswork and Secure Workload platforms. The latest release for Crosswork resolves four high-severity issues, including CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, which enable risks such as SQL injection and remote code execution, alongside CVE-2026-20359 involving credential protection failures. Secure Workload versions 4.0.4.16 and 3.10.9.1 fix five similar critical-class vulnerabilities covering access control, command injection, and buffer overflow concerns. While no active exploitation has been reported, the vendor advises users to apply these patches promptly to mitigate potential unauthorized system access.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.