Cisco Patches Four Maximum-Severity Flaws in Crosswork Network Software

Fifteen vulnerabilities fixed across Cisco products, with three scoring a perfect 10 out of 10 on the standard severity scale. None are known to be exploited yet.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial shot of a dimly lit enterprise telecom server rack with VoIP gateway hardware and blinking amber status LEDs, blue-green ambient light
Share

Key points

  • Cisco released patches on Wednesday for 15 vulnerabilities spread across several of its products.
  • Three flaws in Crosswork version 7.2.1-SP earned a CVSS score of 10 out of 10, the highest possible danger rating.
  • Secure Workload received fixes for five grouped vulnerability sets, four of them rated critical.
  • Cisco says none of the 15 vulnerabilities have been exploited in the wild, meaning seen in real attacks.
  • No action is required from end-users; patching is the responsibility of the IT teams who run these products.

Cisco, the American company best known for making the networking equipment that keeps the internet running, pushed out fixes Wednesday for 15 security flaws across a range of its business software products. The most serious sit inside a product called Crosswork, which businesses use to automate and monitor their networks.

How bad are the Crosswork flaws?

Three of the four Crosswork bugs scored a perfect 10 on the CVSS scale, a standard 0-to-10 measuring stick that security professionals use to rank how dangerous a flaw is. A score of 10 means a criminal could potentially take over an affected system entirely, from anywhere on the internet, with no password needed.

The four CVEs (Common Vulnerabilities and Exposures, the official numbering system for catalogued security flaws) are CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359. The first three cover SQL injection (where an attacker tricks a database into obeying malicious commands), missing authentication (no password check at all), and a bug that lets outsiders control which files the system reads. The fourth, scoring 9.9 out of 10, involves poorly protected login credentials.

All four are fixed in Crosswork version 7.2.1-SP.

What about Cisco's other affected products?

Secure Workload, software that monitors and protects data-centre traffic, also got a significant patch bundle. Five grouped vulnerability sets were fixed in versions 4.0.4.16 and 3.10.9.1, four of them rated critical. The flaws cover broken access controls, command injection (where attackers slip malicious instructions into the software), and input handling bugs.

Product Fixed Version Critical CVEs Highest CVSS
Crosswork 7.2.1-SP 4 10.0
Secure Workload 4.0.4.16 / 3.10.9.1 4 Critical
BroadWorks RI.2026.07 0 High
Unified Intelligence Center Various 0 Medium
RoomOS Various 0 Medium

Cisco's BroadWorks platform, used by telephone and communications providers, received a fix for a high-severity flaw tracked as CVE-2026-20320. The bug sits in the software's XML parser, the part that reads specially formatted data files. An attacker could send a crafted message to trick BroadWorks into handing over sensitive configuration files, no password required. That is a classic XXE (XML External Entity) attack, and it is about as old-school a web security mistake as they come. Fixed in BroadWorks version RI.2026.07.

Medium-severity patches also landed for Unified Intelligence Center, RoomOS (the software on Cisco's video-conferencing devices), Industrial Ethernet 1000 series switches, and two contact centre products.

Should ordinary people be worried?

Not directly. These are enterprise products managed by IT departments, not apps on your phone. Cisco told SecurityWeek it has no evidence any of these flaws have been used in real attacks. That said, scores of 10 attract attention quickly once patches are public, because criminals can study the fix to reverse-engineer what was broken.

If your employer uses Cisco Crosswork or Secure Workload, the sensible question to ask your IT team is: have we applied this week's Cisco updates?

© 2026 Threat Vectr