Cisco just shipped five separate CVSS 10.0 vulnerabilities in a single release

Not in a router. In the software that manages your routers.

Nine flaws across Cisco Crosswork and Cisco Secure Workload, published 19 August 2026. Five scored a perfect 10.0 — the ceiling.

WHAT ACTUALLY HAPPENED

CVE-2026-20030 is an SQL injection. CVE-2026-20357 is missing authentication on a critical function — no credentials required. CVE-2026-20358 gives external control over the file system. CVE-2026-20359 (CVSS 9.9) exposes insufficiently protected credentials. Four of the nine flaws land in Crosswork, the other five in Secure Workload.

Together they enable authentication bypass, command injection, credential compromise and file manipulation on the platform itself. Crosswork 7.2.1 and earlier are affected, fixed in 7.2.1-SP. Secure Workload is hit in both on-premises and SaaS deployments, fixed in 3.10.9.1 and 4.0.4.16.

Cisco found these internally and reports no exploitation in the wild. That is the good news, and it has a shelf life measured in days once patch diffing starts.

WHY THE ORCHESTRATION PLANE CHANGES THE MATH

A 10.0 on a single edge device costs you one device. A 10.0 on the platform that automates, inventories and enforces policy across the estate costs you the estate.

Crosswork holds device credentials, topology and change automation. Secure Workload holds your segmentation policy — the rules deciding which workload may talk to which. An attacker who owns that does not need to break your microsegmentation. They rewrite it, and everything downstream enforces their version faithfully.

Management platforms also sit on the trusted side of the network, thinly monitored, patched on a slow cycle because "they are not exposed." Neither assumption survives an unauthenticated flaw. An orchestration console carrying a public CVE on a quarterly patch cadence is a standing invitation.

WHAT TO DO NOW

PATCH BEFORE THE NEXT MAINTENANCE WINDOW — Crosswork to 7.2.1-SP, Secure Workload to 3.10.9.1 or 4.0.4.16; no workarounds are published for the critical set.

DO NOT SKIP THE SAAS TENANT — Secure Workload SaaS is in scope, so verify your tenant version instead of assuming the vendor handled it.

FENCE THE MANAGEMENT PLANE — restrict orchestration interfaces to a dedicated admin network with MFA, not to every internal host.

ROTATE WHAT THE PLATFORM STORES — treat device credentials and API keys held by Crosswork as exposed until you have patched and reviewed access logs.

Your network is only as segmented as the console that writes the rules.

Do you patch your management platforms on the same clock as your production devices — or on a slower one?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.