Cisco released fixes for critical security holes in Crosswork that could let attackers break in remotely, bypass login checks, and alter or delete files. Crosswork version 7.2.1-SP fixes CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359, which cover SQL injection, missing authentication, external control of the file system, and weak credential protection. Cisco says it is not aware of in-the-wild exploitation.
Why it matters: Organizations running Cisco Crosswork should treat this as a high-priority update because the flaws are critical and affect management software that can expose broad network control. Patch quickly and review internet exposure and administrative access.
info@thehackernews.com (The Hacker News)
2026.08.21
92% relevant
This appears to be the same Cisco disclosure event and adds that the advisory covers nine total flaws across Crosswork and Secure Workload, with five rated CVSS 10.0, expanding beyond the previously tracked Crosswork subset.
Ionut Arghire
2026.08.20
100% relevant
The article establishes a distinct Crosswork patch event with four newly disclosed critical CVEs and concrete fixed version information, separate from the existing Secure Workload story.
← Back to all stories