LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Six Maximum-Severity Flaws Found in Cisco Products

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. […]

zeroday.news ·

Cisco has released a series of security patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, with six of these flaws receiving the maximum CVSS score of 10.0. The vulnerabilities were discovered during an internal security review conducted by Cisco's engineering team, which included the use of advanced AI models. As of the announcement on August 21, 2026, Cisco stated there is no evidence of these vulnerabilities being actively exploited in the wild.

The affected Crosswork products include Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, specifically versions 7.2.1 and earlier. These issues have been resolved in version 7.2.1-SP. Four vulnerabilities were identified in these platforms:

CVE-2026-20030 (CVSS 10.0): An SQL injection flaw that could allow an attacker to manipulate database queries. CVE-2026-20357 (CVSS 10.0): A missing authentication vulnerability for critical functions, enabling unauthorized operations. CVE-2026-20358 (CVSS 10.0): An external control of file system vulnerability, which could permit an external actor to influence file operations. CVE-2026-20359 (CVSS 9.9): An insufficiently protected credentials vulnerability, indicating inadequate security for stored login information.

Additionally, five vulnerabilities were patched in Cisco Secure Workload, impacting both its cloud SaaS and on-premises deployments. These fixes are available in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier versions, and 4.0.4.16 for the 4.0 branch. The Secure Workload vulnerabilities include:

CVE-2026-20231 (CVSS 9.9): A cluster of improper neutralization of special elements vulnerabilities, encompassing command, operating system, and argument injection. CVE-2026-20315 (CVSS 10.0): A set of improper access control vulnerabilities, covering issues with authorization, authentication, privileges, and bypasses. CVE-2026-20317 (CVSS 10.0): A group of improper authentication vulnerabilities, including missing authentication, authentication bypass, and reliance on untrusted inputs. CVE-2026-20318 (CVSS 9.6): A collection of improper input validation vulnerabilities, such as input validation, path traversal, and external path control. CVE-2026-20319 (CVSS 7.5): A set of improper restriction of operations within memory buffer vulnerabilities, including buffer overflows and out-of-bounds writes.

Cisco has grouped these issues by their Common Weakness Enumeration (CWE) class and assigned a single Common Vulnerabilities and Exposures (CVE) ID to each grouping to streamline the disclosure process and assist customers with patching. The company emphasizes that these vulnerabilities were discovered internally and are not known to be under active attack. However, the high CVSS scores, particularly the six maximum-severity flaws, suggest that organizations using these Cisco products should prioritize applying the available patches.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Critical Isolated-vm Vulnerability Leads to RCE on Host

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.

vulnerability

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

breach

SickKids data breach exposes employee and job applicant info

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

CVE-2026-19478critical

GitLab Critical GraphQL Flaw Actively Exploited

GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

North Korean Hackers Tied to Rust Supply Chain Attack

Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks