Skip to content
Cisco security vulnerabilities: attackers can bypass Secure Workload login

Cisco security vulnerabilities: attackers can bypass Secure Workload login

Heise.De • August 20, 2026

To prevent possible attacks, network administrators should install the current security patches from Cisco . Several products from the network equipment manufacturer are affected by “ critical ” security vulnerabilities. So far, there are no indications that attackers are already exploiting the weaknesses.

Specifically impacted are, among others, the cloud and data center security platform Secure Workload, the automation and monitoring platform Crosswork, the cloud telephony solution BroadWorks, and the customer service platform Packaged Center Enterprise.

Since a list of vulnerable and repaired versions would exceed the scope of this report, administrators can find this information in the security advisories linked below this article.

Secure Workload is vulnerable through a total of five flaws. Four of these are considered “ critical ”, and two of them are rated with the maximum CVSS score of 10 out of 10 (CVE-2026-20315, CVE-2026-20317). In both cases, attackers can bypass authentication through an unspecified method and thus access instances.

Crosswork is vulnerable through four “ critical ” vulnerabilities. The highest possible CVSS score of 10 out of 10 has also been assigned to three of them. At these points, attackers can execute malicious code (CVE-2026-20030), bypass authentication for critical functions (CVE-2026-20357), and gain control over the file system (CVE-2026-20358).

Furthermore, the developers have repaired Cisco Talos intelligence for Enterprise Security Cloud and closed several security vulnerabilities . In the worst case, this could lead to the execution of malicious code (CVE-2026-76404 “ critical ”). According to the developers, **Release 1.0.3** is protected against this.

List sorted by threat level in descending order:

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.