Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: crosswork (2 articles)Clear

Cisco patches nine Crosswork and Secure Workload flaws, five rated a perfect ten

Cisco released fixes for nine vulnerabilities across its Crosswork network-automation platforms and Secure Workload software, five of them rated 10.0. Four affect Crosswork Data Gateway, Network Controller, and Planning regardless of configuration, and include a SQL injection flaw, a missing-authentication flaw, and external control of the file system, each scored 10.0, plus an insufficiently protected credentials issue at 9.9. Five more affect Secure Workload in both cloud and on-premises deployments, led by a 10.0 improper access control flaw and a 9.9 command-injection flaw. Cisco found them in internal testing using AI models and says none are exploited yet, but there are no workarounds, so patching is the only fix.

Check
Upgrade Crosswork to 7.2.1-SP and Secure Workload to 3.10.9.1 or 4.0.4.16, and note that Secure Workload cloud tenants must still upgrade agent and connector software themselves.
Affected
Organizations running Cisco Crosswork 7.2.1 or earlier, or Secure Workload 3.10 or 4.0 branches; multiple 10.0 flaws allow SQL injection, authentication bypass, file-system control, and command injection, with no workarounds.
Fix
Apply the fixed releases promptly since there are no workarounds, prioritize internet-reachable instances, and for Secure Workload cloud deployments confirm agent and connector components are upgraded, not just Cisco's cluster.

Cisco network management products have a flaw that lets attackers crash them remotely - victims need to manually reboot the device to recover (CVE-2026-20188)

Cisco patched a high-severity denial-of-service flaw in Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO) that lets unauthenticated remote attackers exhaust connection resources and force the system into an unresponsive state. CVE-2026-20188. Recovery requires manual reboot. Cisco's PSIRT has not seen exploitation in the wild yet, but Cisco previously patched similar DoS bugs (CVE-2025-20362, CVE-2025-20333) that ended up being weaponized to force ASA and FTD firewalls into reboot loops, which CISA addressed with an emergency directive in November 2025.

Check
Inventory Cisco CNC and Cisco NSO instances. Check whether their management interfaces are reachable from untrusted networks. Set up monitoring alerts for connection-resource exhaustion on these systems.
Affected
Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO) running unpatched versions. CVE-2026-20188, high severity. The DoS condition requires manual reboot to recover, meaning a successful attack creates extended outages. Service-provider and enterprise customers using Cisco network orchestration are in scope.
Fix
Upgrade Cisco CNC and NSO to fixed versions per Cisco's advisory. Restrict management interfaces to trusted internal networks. Implement rate limiting at the network edge to throttle connection attempts to CNC/NSO ports. Document recovery procedures including console access for manual reboot - a remote-only management plan fails if the box itself becomes unreachable.