Back to Local Business

Cisco releases patches for critical flaws in Crosswork and Secure Workload

Cisco has issued updates to address 15 security vulnerabilities, including critical defects in Crosswork and Secure Workload that could allow remote code execution.

Opal Keller

August 20, 20261 min read

Software Security Patches - illustration, Jake Team LLC

Cisco announced the release of patches for 15 vulnerabilities across its product lineup, addressing critical and high-severity flaws in Crosswork and Secure Workload. The company stated that it is not aware of any active exploitation of these defects in the wild.

Crosswork version 7.2.1-SP includes fixes for four critical-severity vulnerabilities. Three of these, identified as CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, carry a maximum CVSS score of 10.0. The fourth, CVE-2026-20359, has a score of 9.9.

Cisco noted that these identifiers group multiple issues under common vulnerability classes, including SQL injection, missing authentication, external control of file systems, and insufficient credential protection. Successful exploitation could enable remote code execution, authentication bypass, path traversal, and file manipulation attacks.

Secure Workload versions 4.0.4.16 and 3.10.9.1 address five additional vulnerabilities, four of which are rated critical. These include improper access control and authentication bugs (CVE-2026-20315 and CVE-2026-20317), code and OS command injections (CVE-2026-20231), and input validation and path traversal issues (CVE-2026-20318). A fifth vulnerability, CVE-2026-20319, covers buffer overflows and out-of-bounds write issues.

A high-severity flaw in the BroadWorks Open Client Interface XML parser, tracked as CVE-2026-20320, was also resolved. This defect allowed remote attackers to read sensitive configuration information without authentication by sending crafted XML messages, due to external entity resolution being enabled by default.

Fixes for this issue are included in version RI.2026.07 of the BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform.

Cisco also released fixes for medium-severity weaknesses in Unified Intelligence Center, RoomOS, Industrial Ethernet 1000 series switches, and Packaged Contact Center Enterprise. Further details are available on the company’s security advisories page.

Cisco employs about 2,000 people in Richardson, according to local government records.

Source: SecurityWeek.

Sources

https://www.securityweek.com/cisco-patches-critical-crosswork-secure-workload-vulnerabilities/

Share

Opal Keller

Opal Keller reports on local business, new openings, and economic development in Richardson.

Related Stories

Local Business

CAPA adds Caliber and GEICO executives to board

The Certified Automotive Parts Association announced the election of two new board members from the insurance and collision repair sectors.

Opal KellerAugust 26, 20261 min read

More in Richardson

Richardson

City Council Approves Service Center Roof and Maintenance Contract

The city council will consider a cooperative job order contract through the TIPS purchasing system for roof replacement, painting, wall sealing, window glazing, and control joint work at the service center. The approved amount is $415,077.32.

Reese PenningtonAugust 22, 20261 min read