HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Cisco Patches Nine Critical Flaws in Crosswork & Secure Workload, Five Rated CVSS 10.0

Cisco released patches for nine vulnerabilities across its Crosswork and Secure Workload platforms, with five flaws scoring a perfect CVSS 10.0. Organizations must treat these as high‑priority remediation to satisfy SOC 2 change‑management and risk‑management controls.

LiveThreat™ Intelligence · 📅 August 21, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Cisco Patches Nine Critical Flaws in Crosswork & Secure Workload, Five Rated CVSS 10.0

What Happened – Cisco released security updates for its Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload products, fixing nine vulnerabilities. Five of the flaws received a maximum CVSS 10.0 severity rating, indicating remote code execution or full system compromise potential.

Why It Matters for Compliance & Audit Readiness

  • Unpatched critical flaws directly violate SOC 2 CC6.1 (Change Management) and CC7.1 (Risk Management) requirements for timely remediation.
  • Demonstrating a documented, repeatable patch‑management process provides audit‑ready evidence that your organization controls the vulnerability lifecycle.
  • Continuous evidence collection on patch status feeds the Trust Center, enabling real‑time proof of compliance to auditors and customers.

Who Is Affected – Enterprises that run Cisco Crosswork automation or Secure Workload in data‑center, cloud, or hybrid environments – spanning technology, telecom, financial services, and manufacturing sectors.

Recommended Actions

  • Inventory all Cisco Crosswork and Secure Workload instances.
  • Map each disclosed CVE to your change‑management control (SOC 2 CC6.1).
  • Apply the Cisco patches within your organization’s defined remediation window.
  • Capture patch‑deployment logs and retain them as continuous compliance evidence.

Technical Notes – The nine flaws include remote code execution via unauthenticated network requests, privilege‑escalation paths, and authentication bypasses. All affect the core services of Crosswork regardless of configuration. CVE identifiers and CVSS scores are listed in Cisco’s advisory. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →