INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Six Maximum-Severity Flaws Found in Cisco Products
| 2026-08-21 12:30 CRITICAL HIGHExecutive Summary AI-generated
The recent incident data reveals a critical vulnerability in Cisco products, with six maximum-severity flaws found in the company's software. These vulnerabilities were identified through internal testing and patched by Cisco to prevent exploitation. The most severe flaw was rated CVSS 10.0, indicating its potential impact on systems worldwide. The patches also addressed four other vulnerabilities that affected various components of Cisco's products, including Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning. These flaws were exploited through SQL injection, missing authentication, external control of file systems, insufficiently protected credentials, improper input validation, buffer overflows, out-of-bounds writes, improper access control, and improper restriction of operations within the bounds of a memory buffer vulnerabilities. The patches also fixed five vulnerabilities in Cisco Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and four.0.4.16 for the 4.0 branch.
Technical Mitigations AI-generated
* Implement secure coding practices and follow best security guidelines to prevent similar vulnerabilities from occurring in the future.
* Regularly review and update software dependencies, including libraries and frameworks, to ensure they have the latest security patches and updates.
* Conduct thorough vulnerability scanning and penetration testing of systems and networks to identify potential weaknesses before they can be exploited.
* Educate users and administrators on how to properly configure and use Cisco products to minimize the risk of vulnerabilities being introduced or exploited.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20349CVE-2026-20349
CVE-2026-20030CVE-2026-20030
CVE-2026-20317CVE-2026-20317
CVE-2026-20319CVE-2026-20319
CVE-2026-20315CVE-2026-20315
CVE-2026-20357CVE-2026-20357
CVE-2026-20358CVE-2026-20358
CVE-2026-20231CVE-2026-20231
CVE-2026-20359CVE-2026-20359
CVE-2026-20318CVE-2026-20318
Target & Sectors
Global Scope
defensedefense
Incident Timeline
Aug 21, 2026
Threat actors exploited six maximum-security vulnerabilities in Cisco products to gain unauthorized access and control.
2026/08/21
Cisco patched nine critical flaws in its Cisco Secure Workload and Crosswork products.
Click on any entity below to view its context and source!
organisation
Secure Workload Flaws
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0.
organisation
Crosswork Data Gateway
Four vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, all impacting these products regardless of how they’re configured:
CVE-2026-20030 (CVSS score: 10.0) – an SQL injection vulnerability that lets an attacker manipulate database queries directly.
organisation
Crosswork Planning
Four vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, all impacting these products regardless of how they’re configured:
CVE-2026-20030 (CVSS score: 10.0) – an SQL injection vulnerability that lets an attacker manipulate database queries directly.
Four of the security vulnerabilities
affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration.
organisation
SQL
Four vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, all impacting these products regardless of how they’re configured:
CVE-2026-20030 (CVSS score: 10.0) – an SQL injection vulnerability that lets an attacker manipulate database queries directly.
An SQL injection vulnerability
CVE-2026-20357
(CVSS score: 10.0) -
organisation
Crosswork Data Gateway,
Four of the security vulnerabilities
affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration.
organisation
CVE-2026-20358
CVE-2026-20358 (CVSS score: 10.0) – an external control of file system vulnerability, letting an outside actor influence which files the system reads or writes.
A missing authentication for critical function vulnerability
CVE-2026-20358
(CVSS score: 10.0) - An external control of file system vulnerability
CVE-2026-20359
(CVSS score: 9.9) -
organisation
CVE-2026-20359
A missing authentication for critical function vulnerability
CVE-2026-20358
(CVSS score: 10.0) - An external control of file system vulnerability
CVE-2026-20359
(CVSS score: 9.9) -
CVE-2026-20359 (CVSS score: 9.9) – an insufficiently protected credentials vulnerability, where stored login material isn’t locked down the way it should be.
infrastructure
9.9
Cisco has also
released fixes
to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) and on-premises deployments -
CVE-2026-20231
(CVSS score: 9.9) -
organisation
Cisco Secure Workload
Cisco has also
released fixes
to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) and on-premises deployments -
CVE-2026-20231
(CVSS score: 9.9) -
infrastructure
7.2.1
The four flaws affect Crosswork 7.2.1 and earlier, and Cisco fixed them in version 7.2.1-SP.
An insufficiently protected credentials vulnerability
The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.
infrastructure
7.2.1-SP
The four flaws affect Crosswork 7.2.1 and earlier, and Cisco fixed them in version 7.2.1-SP.
An insufficiently protected credentials vulnerability
The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.
organisation
Cisco Crosswork Release
An insufficiently protected credentials vulnerability
The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.
organisation
CVE-2026-20315
CVE-2026-20315 (CVSS score: 10.0) – a set of improper access control vulnerabilities spanning authorization, authentication, privileges, and bypasses, a broad category that generally means the system doesn’t reliably enforce who’s allowed to do what.
organisation
CVE-2026
A set of improper neutralization of special elements vulnerabilities spanning command, operating system, and argument injection
CVE-2026-20315
(CVSS score: 10.0) -
infrastructure
3.10.9
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
infrastructure
3.10
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
infrastructure
4.0.4
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
infrastructure
4.0
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
organisation
Secure Workload Release 3.10.9.1
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
organisation
Maximum-Severity Flaws Found
Six Maximum-Severity Flaws Found in Cisco Products.
organisation
Crosswork
Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.
Ravie Lakshmanan
Aug 21, 2026
Vulnerability / Enterprise Security
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.
organisation
Secure Workload
Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.
Ravie Lakshmanan
Aug 21, 2026
Vulnerability / Enterprise Security
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.
organisation
CVSS
Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.
Earlier this month, Cisco
warned
that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.
organisation
Vulnerability / Enterprise Security
Ravie Lakshmanan
Aug 21, 2026
Vulnerability / Enterprise Security
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.
infrastructure
8.6
Earlier this month, Cisco
warned
that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.
organisation
Secure Firewall Adaptive Security Appliance
Earlier this month, Cisco
warned
that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.
organisation
Secure Firewall Threat Defense
Earlier this month, Cisco
warned
that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.
organisation
the Cisco Crosswork
“As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review.
organisation
CWE
To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class – Common Weakness Enumeration (CWE) – and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.”
organisation
Nobody’s
Nobody’s reported active attacks against any of these nine flaws yet, and Cisco’s own review process caught them before an outside researcher or attacker did.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Cisco)
infrastructure
Ios
The development comes about two weeks after Cisco resolved
12 bugs impacting Catalyst SD-WAN and IOS XE Software
following the internal security review.
organisation
Catalyst SD-WAN
The development comes about two weeks after Cisco resolved
12 bugs impacting Catalyst SD-WAN and IOS XE Software
following the internal security review.
organisation
IOS XE
The development comes about two weeks after Cisco resolved
12 bugs impacting Catalyst SD-WAN and IOS XE Software
following the internal security review.
Tactical Metrics
Metrics
infrastructure
7.2.1
Software Version
Click for context!
The four flaws affect Crosswork 7.2.1 and earlier, and Cisco fixed them in version 7.2.1-SP.
An insufficiently protected credentials vulnerability
The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.
Metrics
infrastructure
7.2.1-SP
Software Version
The four flaws affect Crosswork 7.2.1 and earlier, and Cisco fixed them in version 7.2.1-SP.
An insufficiently protected credentials vulnerability
The issues affect Cisco Crosswork Release version 7.2.1 and earlier, and have been addressed in version 7.2.1-SP.
Metrics
infrastructure
3.10.9
Software Version
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
Metrics
infrastructure
3.10
Software Version
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
Metrics
infrastructure
4.0.4
Software Version
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
Metrics
infrastructure
4.0
Software Version
The networking giant
addressed five vulnerabilities
in Secure Workload Release 3.10.9.1 for the 3.10 branch and earlier, and 4.0.4.16 for the 4.0 branch.
A set of improper restriction of operations within the bounds of a memory buffer vulnerabilities spanning buffer overflows and out-of-bounds writes
The five vulnerabilities have been patched in the versions below -
Cisco Secure Workload Release version 3.10 and earlier - Fixed in 3.10.9.1
Cisco Secure Workload Release version 4.0 - Fixed in 4.0.4.16
"These vulnerabilities were found during internal testing and are not known to be actively exploited," the company said, urging customers to apply the necessary updates to avoid future exposure.
Metrics
infrastructure
8.6
Software Version
Earlier this month, Cisco
warned
that a vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software (CVE-2026-20349, CVSS score: 8.6) has been exploited in the wild.
Metrics
infrastructure
9.9
Software Version
Cisco has also
released fixes
to remediate five vulnerabilities affecting Cisco Secure Workload, including Software-as-a-Service (SaaS) and on-premises deployments -
CVE-2026-20231
(CVSS score: 9.9) -
Metrics
infrastructure
Ios
Affected Product
The development comes about two weeks after Cisco resolved
12 bugs impacting Catalyst SD-WAN and IOS XE Software
following the internal security review.
Intelligence Sources
Security Affairs
2026-08-21
Six Maximum-Severity Flaws Found in Cisco Products
Security Affairs
The Hacker News
2026-08-21
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-22T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
25x
organisation
Identified Entity
Crosswork Data Gateway
entity
10x
vulnerability
Exploited CVE
CVE-2026-20030
cve
8x
infrastructure
Software Version
7.2.1
version
2x
general metric
Cve-2026 Cvss Score
10
cve-2026 cvss score
2x
general metric
Branch
3
branch
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
timeline
Temporal Reference
Aug 21, 2026
date
2x
general metric
Aug
21
aug
Contextual Telemetry
Context Block
6 METRICS
vulnerability
CVSS Score
10
score
general metric
Cvss Score
10
cvss score
industry
Targeted Sector
Defense
sector
general metric
Software
9
software
infrastructure
Affected Product
Ios
software
general metric
Bugs
12
bugs
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.