Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Cisco Patches Nine Critical Flaws in Crosswork & Secure Workload, Five Rated CVSS 10.0

Cisco released patches for nine vulnerabilities across its Crosswork and Secure Workload platforms, with five flaws scoring a perfect CVSS 10.0. Organizations must treat these as high‑priority remediation to satisfy SOC 2 change‑management and risk‑management controls.

LiveThreat™ Intelligence · 📅 August 21, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

Cisco Patches Nine Critical Flaws in Crosswork & Secure Workload, Five Rated CVSS 10.0

What Happened – Cisco released security updates for its Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload products, fixing nine vulnerabilities. Five of the flaws received a maximum CVSS 10.0 severity rating, indicating remote code execution or full system compromise potential.

Why It Matters for Compliance & Audit Readiness

  • Unpatched critical flaws directly violate SOC 2 CC6.1 (Change Management) and CC7.1 (Risk Management) requirements for timely remediation.
  • Demonstrating a documented, repeatable patch‑management process provides audit‑ready evidence that your organization controls the vulnerability lifecycle.
  • Continuous evidence collection on patch status feeds the Trust Center, enabling real‑time proof of compliance to auditors and customers.

Who Is Affected – Enterprises that run Cisco Crosswork automation or Secure Workload in data‑center, cloud, or hybrid environments – spanning technology, telecom, financial services, and manufacturing sectors.

Recommended Actions

  • Inventory all Cisco Crosswork and Secure Workload instances.
  • Map each disclosed CVE to your change‑management control (SOC 2 CC6.1).
  • Apply the Cisco patches within your organization’s defined remediation window.
  • Capture patch‑deployment logs and retain them as continuous compliance evidence.

Technical Notes – The nine flaws include remote code execution via unauthenticated network requests, privilege‑escalation paths, and authentication bypasses. All affect the core services of Crosswork regardless of configuration. CVE identifiers and CVSS scores are listed in Cisco’s advisory. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →