Cisco Vulnerabilities Allow Bypass of Secure Workload Login

Cisco Vulnerabilities Allow Bypass of Secure Workload Login

First seen 20 Aug 2026, 18:28 UTC Heise.Deadvisory.splunk.comwww.heise.desec.cloudapps.cisco.com 89% similarity 74.0

Article Content

Browse articles
ThreatCluster

Cisco has disclosed multiple critical vulnerabilities affecting several of its products, including Secure Workload, Crosswork, BroadWorks, and Packaged Center Enterprise. Network administrators are urged to install the latest security patches to mitigate the risks. Secure Workload is vulnerable through five flaws, four of which are critical, with two rated CVSS 10/10 (CVE-2026-20315, CVE-2026-20317). Attackers can bypass authentication and gain unauthorized access to instances. Crosswork has four critical vulnerabilities, three also rated CVSS 10/10, allowing for malicious code execution and file system control. Cisco Talos Intelligence for Enterprise Security Cloud has also been patched for critical vulnerabilities. As of now, there are no indications that these vulnerabilities are being actively exploited.

Key Points: • Cisco products affected include Secure Workload, Crosswork, and BroadWorks. • Five critical vulnerabilities in Secure Workload allow authentication bypass. • Network admins should apply the latest security patches immediately.

ThreatCluster AI How this analysis works

Timeline

2026-08-19
CVE-2026-20315 published
A critical vulnerability allowing authentication bypass in Secure Workload was disclosed.
Heise.De
2026-08-19
CVE-2026-20317 published
Another critical flaw in Secure Workload was published, also allowing authentication bypass.
Heise.De
2026-08-19
CVE-2026-20030 published
A critical vulnerability in Crosswork enabling malicious code execution was disclosed.
Heise.De
2026-08-19
CVE-2026-20357 published
A critical flaw in Crosswork allowing authentication bypass for critical functions was disclosed.
Heise.De
2026-08-19
CVE-2026-20358 published
A critical vulnerability in Crosswork allowing file system control was disclosed.
Heise.De
2026-08-19
CVE-2026-76404 published
Critical vulnerabilities in Cisco Talos Intelligence for Enterprise Security Cloud were disclosed.
Heise.De

Community

Browse all →