Six CVSS 10.0 Vulnerabilities Disclosed in Cisco Crosswork and Secure Workload Products
What Happened — Cisco released patches for nine critical flaws, including six rated CVSS 10.0, affecting its Crosswork Data Gateway, Network Controller, Planning, and Secure Workload solutions. The vulnerabilities span SQL injection, missing authentication, file‑system control, credential exposure, and multiple improper access‑control issues. None have been observed in the wild.
Why It Matters for Compliance & Audit Readiness
- These flaws illustrate gaps that SOC 2 control‑mapping must capture: every critical function needs documented safeguards and evidence of remediation.
- Continuous evidence collection (e.g., patch‑status logs, configuration baselines) provides the audit trail required to demonstrate that “Security” and “Availability” criteria are being actively managed.
- Mapping each CVE to the relevant Trust Services Criteria (e.g., CC6.1 – Logical Access Controls) helps prove due diligence during a SOC 2 audit.
Who Is Affected – Enterprises that deploy Cisco Crosswork or Secure Workload in on‑premises data centers or as SaaS workloads, spanning telecom, cloud service providers, and large‑scale IT operations.
Recommended Actions
- Verify your inventory and confirm you are running Cisco 7.2.1‑SP or later for all affected components.
- Capture patch‑installation timestamps and retain logs as SOC 2 evidence of “Vulnerability Management”.
- Update your control‑mapping matrix to reflect the new remediation steps for logical access, authentication, and input validation controls.
Source: Security Affairs
Technical Notes – The advisory groups the flaws by CWE, assigning a single CVE per class. Highlights:
- CVE‑2026‑20030 (SQL injection, CVSS 10.0)
- CVE‑2026‑20357 (Missing authentication, CVSS 10.0)
- CVE‑2026‑20358 (External control of file system, CVSS 10.0)
- CVE‑2026‑20359 (Insufficiently protected credentials, CVSS 9.9)
- CVE‑2026‑20231 (Command/OS injection, CVSS 9.9)
- CVE‑2026‑20315 & CVE‑2026‑20317 (Improper access/authentication, CVSS 10.0)