Cisco Patches 9 Flaws, 5 Scored CVSS 10.0 — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Cisco released patches for nine vulnerabilities across Crosswork platforms and Secure Workload software, with five scoring the maximum CVSS 10.0 severity rating.
- Crosswork Data Gateway, Network Controller, and Planning were hit by four flaws—three CVSS 10.0 (SQL injection, missing authentication for critical function, and external file system control) plus a 9.9 credential protection issue—affecting version 7.2.1 and earlier, fixed in 7.2.1-SP.
- Cisco Secure Workload (SaaS and on-premises) received fixes for five bugs, including two CVSS 10.0 flaws covering access control and authentication bypasses, patched in release 3.10.9.1 (for 3.10 and earlier) and 4.0.4.16.
- Cisco said the vulnerabilities surfaced during internal testing and are not known to be actively exploited, urging customers to apply the updates.
- The patches follow roughly two weeks after Cisco resolved 12 bugs in Catalyst SD-WAN and IOS XE Software through the same ongoing internal security review.
- Separately, Cisco warned earlier this month that CVE-2026-20349, a CVSS 8.6 flaw in Secure Firewall ASA and FTD Software, has been actively exploited in the wild.
Why it matters: Five of the nine newly patched flaws carry the maximum CVSS 10.0 score, with at least three enabling pre-authentication compromise of network management infrastructure—high-value footholds given Cisco's deep footprint in enterprise networks. While Cisco says none of the nine are yet exploited, the disclosure lands just weeks after the company confirmed CVE-2026-20349 was being weaponized against Secure Firewall appliances, illustrating how a single uncaught flaw can become an active threat.
Ask SkimNews




