Cisco published security advisories on August 19, 2026, to address nine vulnerabilities affecting its Crosswork and Secure Workload products. The update includes five flaws rated as Critical, each carrying a Common Vulnerability Scoring System score of 10.0.
The company stated that these weaknesses were identified during internal security testing and that it was not aware of any exploitation in the wild at the time of release.
Cisco Crosswork is a network automation platform used by service providers and large enterprises to manage infrastructure. Cisco Secure Workload, formerly known as Tetration, monitors application communications and enforces segmentation policies across cloud and data center environments. Because both platforms typically operate with privileged access to infrastructure and security management functions, the vulnerabilities present significant risks if exploited.
The Crosswork flaws include SQL injection, missing authentication, external control of the file system, and insufficiently protected credentials. Cisco noted that successful exploitation could lead to authentication bypass, path traversal, credential exposure, file overwrite or deletion, and in some cases, remote code execution. The Secure Workload vulnerabilities involve command and operating system injection, improper access control, improper authentication, path traversal weaknesses, and memory corruption issues.
Four of these five Secure Workload flaws received Critical severity ratings, with potential impacts including unauthorized access, command execution, and manipulation of security controls.
The vulnerabilities were disclosed as part of a security hardening initiative and were grouped by type rather than assigned separate identifiers for each weakness. Cisco reported that no public proof-of-concept exploits had been identified when the advisories were released.