Cisco has released urgent security patches to address 15 vulnerabilities, including several with a maximum CVSS score of 10/10. These flaws in Crosswork and Secure Workload could allow attackers to execute remote code and bypass authentication.
- Cisco addressed 15 vulnerabilities across multiple product lines.
- Three CVEs in Crosswork received a maximum CVSS score of 10/10.
- Risks include Remote Code Execution (RCE) and authentication bypass.
- No active exploitation has been detected in the wild so far.
Networking giant Cisco announced on Wednesday the release of critical security patches to mitigate 15 vulnerabilities across its product portfolio. The most alarming flaws were identified in Cisco Crosswork and Secure Workload, posing significant risks to enterprise infrastructure.
Maximum Severity: The 10/10 Threat
In the Crosswork 7.2.1-SP update, Cisco addressed four critical-severity CVEs. Notably, three of these—CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358—have been assigned a maximum CVSS score of 10/10. These vulnerabilities encompass SQL injection, missing authentication, and external control of the file system. A fourth vulnerability, CVE-2026-20359, follows closely with a near-perfect severity rating of 9.9/10, involving insufficient credential protection.
An attacker successfully exploiting these defects could achieve Remote Code Execution (RCE), bypass authentication protocols, perform path traversal, or engage in unauthorized file deletion and overwriting.
Secure Workload and BroadWorks Updates
Cisco also rolled out updates for Secure Workload (versions 4.0.4.16 and 3.10.9.1) to fix five CVEs, four of which are classified as critical. These include improper access control and OS command injections. Furthermore, a high-severity defect in the BroadWorks Open Client Interface (OCI) XML parser (CVE-2026-20320) was resolved, preventing attackers from reading sensitive configuration data through crafted XML messages.
Security experts warn that vulnerabilities with a 10/10 rating represent the highest possible tier of risk to digital assets.
Why This Matters: BozokMedia Analysis
BozokMedia analysis shows that as organizations transition toward automated, software-defined networking, the attack surface shifts from physical hardware to orchestration layers like Crosswork. A compromise at this level doesn't just affect one device; it can compromise the entire network's integrity and logic.
Historical Background
The landscape of cybersecurity has shifted from simple malware to sophisticated exploits targeting the very software that manages global networks. The increasing frequency of high-severity CVEs in core networking software highlights the growing tension between rapid feature deployment and robust security auditing.
Frequently Asked Questions
Question 1: Are these vulnerabilities being exploited currently?
Answer: Cisco has stated they are not aware of any of these vulnerabilities being exploited in the wild.
Question 2: Which products are most affected?
Answer: Cisco Crosswork, Secure Workload, and BroadWorks are among the most critically impacted products.