Cisco Patches Nine Critical Flaws in Crosswork & Secure Workload, Five Rated CVSS 10.0
What Happened – Cisco released security updates for its Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload products, fixing nine vulnerabilities. Five of the flaws received a maximum CVSS 10.0 severity rating, indicating remote code execution or full system compromise potential.
Why It Matters for Compliance & Audit Readiness
- Unpatched critical flaws directly violate SOC 2 CC6.1 (Change Management) and CC7.1 (Risk Management) requirements for timely remediation.
- Demonstrating a documented, repeatable patch‑management process provides audit‑ready evidence that your organization controls the vulnerability lifecycle.
- Continuous evidence collection on patch status feeds the Trust Center, enabling real‑time proof of compliance to auditors and customers.
Who Is Affected – Enterprises that run Cisco Crosswork automation or Secure Workload in data‑center, cloud, or hybrid environments – spanning technology, telecom, financial services, and manufacturing sectors.
Recommended Actions
- Inventory all Cisco Crosswork and Secure Workload instances.
- Map each disclosed CVE to your change‑management control (SOC 2 CC6.1).
- Apply the Cisco patches within your organization’s defined remediation window.
- Capture patch‑deployment logs and retain them as continuous compliance evidence.
Technical Notes – The nine flaws include remote code execution via unauthenticated network requests, privilege‑escalation paths, and authentication bypasses. All affect the core services of Crosswork regardless of configuration. CVE identifiers and CVSS scores are listed in Cisco’s advisory. Source: The Hacker News