Cisco has pushed out fixes for nine vulnerabilities across its Crosswork network tools and Secure Workload micro-segmentation platform, five of them rated at the maximum CVSS score of 10.0.
Four of the flaws hit Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning. The list includes an SQL injection (CVE-2026-20030), a missing-authentication issue (CVE-2026-20357), and an external file-control weakness (CVE-2026-20358), each rated 10.0, plus a 9.9-rated credentials-protection gap (CVE-2026-20359). Crosswork releases up to 7.2.1 are affected, with the fix landing in 7.2.1-SP.
The remaining five bugs affect Secure Workload, the product formerly known as Tetration that stops lateral movement between workloads. Two of them, CVE-2026-20315 and CVE-2026-20317, earned perfect-ten ratings for improper access control and authentication weaknesses, while CVE-2026-20231 (9.9) covers injection issues, CVE-2026-20318 (9.6) covers input validation and path traversal, and CVE-2026-20319 (7.5) covers memory-buffer operations. Updates apply to both SaaS and on-premises deployments.
As with recent Cisco advisories, the patches come out of an ongoing internal security review. Administrators of either product should treat the 10.0-rated issues as urgent, especially where Secure Workload gateways face untrusted networks.
