Cisco Crosswork and Secure Workload Multiple Critical Vulnerabilities
First seen Aug 23, 2026 · Updated Aug 23, 2026 · CVSS 10
Cisco has released patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, five of which carry the maximum CVSS score of 10.0. These flaws affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of device configuration, posing significant risk to network orchestration infrastructure.
Technical Analysis
The disclosed vulnerabilities impact core Cisco Crosswork network automation components (Data Gateway, Network Controller, Planning) and Secure Workload software, with five flaws rated CVSS 10.0 indicating unauthenticated remote code execution or full system compromise potential without user interaction. The raw data does not specify individual CVE identifiers or precise attack vectors (e.g., API authentication bypass, deserialization, or command injection), but the severity and default-configuration applicability suggest these are network-facing services exposed to management interfaces. Organizations using Crosswork for network orchestration and Secure Workload for microsegmentation should treat this as an urgent patching priority given the critical infrastructure role these platforms play. If exploited, attackers could pivot from network management infrastructure to broader enterprise systems, including any hosts running AI agent orchestration, RAG pipelines, or automated network-configuration agents that rely on Crosswork APIs or credentials, potentially exposing agent-accessible API keys or enabling lateral movement into agent-integrated environments.
Affected Systems
Cisco Crosswork Data Gateway (all configurations), Cisco Crosswork Network Controller, Cisco Crosswork Planning, Cisco Secure Workload Software - specific version ranges not detailed in source; organizations should consult Cisco's official security advisories for exact affected versions.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source data - this is a vendor patch disclosure rather than an active exploitation report.
Remediation Steps
- 1
Apply Cisco Security Patches
Immediately review Cisco's official security advisories for Crosswork and Secure Workload products and apply all available patches, prioritizing the five CVSS 10.0-rated vulnerabilities.
- 2
Inventory Exposed Instances
Identify all Crosswork Data Gateway, Network Controller, Planning, and Secure Workload deployments in the environment, including those with default configurations.
- 3
Restrict Network Access
Limit management interface exposure to trusted internal networks only, and enforce network segmentation until patches are validated and applied.
- 4
Audit Credentials and API Keys
Rotate any credentials or API tokens used by these platforms, particularly those accessible to automation or agent-driven network management tools.
- 5
Monitor for Exploitation
Enable logging and monitoring on affected systems to detect anomalous access patterns or exploitation attempts post-disclosure.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.