Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software

Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A network operations center with multiple large displays showing Cisco infrastructure components and security dashboards with critical alert notifications highl
Share

Key points

  • Cisco released patches on Wednesday for 15 vulnerabilities spread across several of its products.
  • Three flaws in Crosswork earned a CVSS score of 10 out of 10, the highest possible danger rating.
  • Secure Workload received fixes for five grouped vulnerability sets, four of them rated critical.
  • Cisco says none of the 15 vulnerabilities have been exploited in the wild, meaning seen in real attacks.
  • Patching is the responsibility of the IT teams who run these products.

Cisco, the American company best known for making the networking equipment that keeps the internet running, pushed out fixes Wednesday for 15 security flaws across several of its business software products. The most serious sit inside a product called Crosswork, which businesses use to automate and monitor their networks. It's the second time this month we've seen Cisco ship a perfect-score patch: on 6 August, Cisco fixed a 10-out-of-10 flaw in its firewall management software that likewise required no password to exploit.

How bad are the Crosswork flaws?

Three of the four Crosswork bugs scored a perfect 10 on the CVSS scale, a standard 0-to-10 measuring stick that security professionals use to rank how dangerous a flaw is. A score of 10 means an attacker could potentially take over an affected system entirely, from anywhere on the internet, with no password needed.

The four CVEs (Common Vulnerabilities and Exposures, the official numbering system for catalogued security flaws) are CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359. CVE-2026-20030 covers SQL injection, where an attacker tricks a database into obeying malicious commands. CVE-2026-20357 involves missing authentication, meaning no password check at all. CVE-2026-20358 lets outsiders control which files the system reads. The fourth, scoring 9.9 out of 10, involves poorly protected login credentials. All four are fixed in Crosswork version 7.2.1-SP.

What about Cisco's other affected products?

Secure Workload, software that monitors and protects data-centre traffic, also got a significant patch bundle. Five grouped vulnerability sets were fixed in versions 4.0.4.16 and 3.10.9.1, four of them rated critical. The flaws cover broken access controls, command injection (where attackers slip malicious instructions into the software), and input handling bugs.

Product Fixed Version Critical CVEs Highest CVSS
Crosswork 7.2.1-SP 4 10.0
Secure Workload 4.0.4.16 / 3.10.9.1 4 Critical
BroadWorks RI.2026.07 0 High
Unified Intelligence Center Various 0 Medium
RoomOS Various 0 Medium

Cisco's BroadWorks, a platform used by telephone and communications providers, received a fix for a high-severity flaw tracked as CVE-2026-20320. It sits in the software's XML parser, the part that reads specially formatted data files. An attacker could send a crafted message to extract sensitive configuration files with no password required. That's a classic XXE (XML External Entity) attack, about as old-school a web security mistake as they come. Fixed in BroadWorks version RI.2026.07.

Medium-severity patches also landed for Unified Intelligence Center, RoomOS (the software on Cisco's video-conferencing devices), Industrial Ethernet 1000 series switches, and two contact centre products.

Should ordinary people be worried?

Not directly. These are enterprise products managed by IT departments, not apps on your phone. Cisco told SecurityWeek it has no evidence any of these flaws have been used in real attacks. Scores of 10 attract attention fast once patches are public, because criminals can study a fix to reverse-engineer what was broken. If your employer runs Cisco Crosswork or Secure Workload, ask your IT team whether this week's Cisco updates have been applied.

© 2026 Threat Vectr