Cisco Systems: 18 Vulnerabilities Disclosed, Including Five Critical Flaws in Crosswork and Secure Workload
Cisco Systems disclosed 18 vulnerabilities on August 19, 2026, including five critical flaws in Crosswork and Secure Workload platforms, with CVSS scores up to 10.0.

Key findings
- 18 Cisco vulnerabilities disclosed on August 19, 2026, impacting multiple product lines.
- Five critical vulnerabilities in Crosswork and Secure Workload platforms, with CVSS scores up to 10.0.
- Vulnerabilities include SQL injection, authentication bypass, and arbitrary code execution.
- Affected products range from enterprise security clouds to contact center solutions and industrial switches.
- Cisco has released patches for all disclosed vulnerabilities.
On August 19, 2026, Cisco Systems disclosed a significant batch of 18 vulnerabilities affecting various products, including Crosswork, Secure Workload, Unified Intelligence Center, BroadWorks, Packaged Contact Center Enterprise, Unified Contact Center Enterprise, RoomOS, Industrial Ethernet switches, and Talos Intelligence for Enterprise Security Cloud. The disclosures, which occurred within a five-hour window, include several critical-severity flaws, with CVSS scores reaching up to 10.0. This coordinated disclosure highlights Cisco's internal security review processes and the ongoing effort to harden its product portfolio.
A group of critical vulnerabilities was identified within Cisco's Crosswork and Secure Workload platforms. CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, all with a CVSS score of 10.0, represent SQL injection, missing authentication for critical functions, and external control of file system vulnerabilities, respectively. Additionally, CVE-2026-20359 and CVE-2026-20231, rated critical at 9.9 and 9.9 respectively, involve insufficiently protected credentials and improper neutralization of special elements. These vulnerabilities were addressed in software hardening releases for these platforms. The Hacker News, SecurityWeek
Other notable vulnerabilities include a blind SQL injection flaw in Cisco Unified Intelligence Center (CVE-2026-20327), an XML External Entity (XXE) injection vulnerability in Cisco BroadWorks allowing sensitive information disclosure (CVE-2026-20320), and a server-side request forgery (SSRF) vulnerability in Cisco Packaged Contact Center Enterprise and Unified Contact Center Enterprise (CVE-2026-20314). Cisco RoomOS is affected by a vulnerability in its USB driver that could allow arbitrary code execution with root privileges (CVE-2026-20302).
Several medium-severity vulnerabilities were also disclosed. CVE-2026-76390 in Cisco Talos Intelligence for Enterprise Security Cloud could allow an unauthenticated user to access the OpenAPI specification. In Cisco Webex app for Splunk SOAR, CVE-2026-76379 allows a user to expose a sensitive meeting password in cleartext. Similarly, CVE-2026-76378 in the Cisco Secure Malware Analytics app for Splunk SOAR exposes a sensitive sample password. Cisco Industrial Ethernet 1000 Series Switches are affected by a stored cross-site scripting (XSS) vulnerability (CVE-2026-20232) and a denial-of-service vulnerability impacting management plane access (CVE-2026-20177). Cyber Security News
Cisco has released software updates to address these vulnerabilities. For the Crosswork and Secure Workload platforms, specific versions were patched as part of software hardening releases. For example, Crosswork version 7.2.1-SP was released with fixes for critical flaws. The Cisco Unified Intelligence Center, BroadWorks, Packaged CCE, Unified CCE, RoomOS, Industrial Ethernet switches, and Talos Intelligence for Enterprise Security Cloud have also received patches. Users are advised to consult Cisco's official advisories for specific version information and remediation steps.
This batch of disclosures underscores the importance of regular security reviews and timely patching for complex enterprise software. The concentration of critical vulnerabilities in core platforms like Crosswork and Secure Workload highlights potential risks for organizations relying on these solutions for network management and security. Users should prioritize applying the available updates to mitigate the risks associated with these vulnerabilities. The Register Security