Cisco just found five perfect-10 bugs in its own network tools — before anyone else did

Nine vulnerabilities, five of them maximum severity, were sitting in the software that runs and secures corporate networks — Cisco caught them…

Aliteq
Ravi Malhotra · Hardware Editor

The short version

Cisco patched 9 CVEs across Crosswork and Secure Workload on August 20, 2026 — 5 of them CVSS 10.0.

The short version

Crosswork flaws (CVE-2026-20030, -20357, -20358) include SQL injection, missing authentication, and unrestricted file writes — fixed in version 7.2.1-SP.

The short version

Secure Workload flaws (CVE-2026-20315, -20317, and three more) hit every version and require upgrading to 4.0.4.16 or 3.10.9.1.

The short version

Cisco says it found all nine internally and has no evidence of exploitation — but that window rarely stays closed for long.

The short version

This is the second CVSS 10.0 bug disclosed in Secure Workload in 2026 alone, after a REST API flaw patched in May.

My honest read

The number that matters here isn't the CVSS score — it's Cisco's own phrase, "regardless of the device configuration." That means there's no hardening setting, no optional flag, that would have…

Aliteq

Read the full story

Cisco just found five perfect-10 bugs in its own network tools — before anyone else did

Read the full story on Aliteq