www.heise.de Cisco Vulnerabilities Allow Bypass of Secure Workload Login
Article Content
- •Cisco products affected include Secure Workload, Crosswork, and BroadWorks.
- •Five critical vulnerabilities in Secure Workload allow authentication bypass.
- •Network admins should apply the latest security patches immediately.
Cisco has disclosed multiple critical vulnerabilities affecting several of its products, including Secure Workload, Crosswork, BroadWorks, and Packaged Center Enterprise. Network administrators are urged to install the latest security patches to mitigate the risks. Secure Workload is vulnerable through five flaws, four of which are critical, with two rated CVSS 10/10 (CVE-2026-20315, CVE-2026-20317). Attackers can bypass authentication and gain unauthorized access to instances. Crosswork has four critical vulnerabilities, three also rated CVSS 10/10, allowing for malicious code execution and file system control. Cisco Talos Intelligence for Enterprise Security Cloud has also been patched for critical vulnerabilities. As of now, there are no indications that these vulnerabilities are being actively exploited.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-20030 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…