ctipilot.ch

Cisco Crosswork / Secure Workload — the ninth CVE of the August 2026 hardening set, absent from the W34 weekly rollup enumeration

cve · CVE-2026-20319

Coverage timeline
1
first 2026-08-22 → last 2026-08-24
Peak priority
notable
1 notable
Sources cited
3
2 hosts
Sections touched
1
updates
Co-occurring entities
8
see Related entities below
ATT&CK techniques
3
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Cisco Crosswork Data GatewayCisco Crosswork Network ControllerCisco Crosswork PlanningCisco Crosswork Workflow ManagerCisco Secure Workload

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves · ATT&CK page ↗

Credential Access TA0006

T1552Unsecured Credentials×1

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-08-24/cisco-crosswork-secure-workload-nine-cwe-grouped-cves · ATT&CK page ↗

Story timeline

  1. 2026-08-24Cisco Crosswork and Secure Workload ship nine CVEs where each identifier stands for a whole class of bugs — six reachable unauthenticated, three at low privilege, and no workaround for any of them
    updatesOne CVE per weakness class means neither platform can be triaged flaw-by-flaw — only by release

Where this entity is cited

  • updates1

Source distribution

  • sec.cloudapps.cisco.com2 (67%)
  • advisories.ncsc.nl1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Cisco Crosswork / Secure Workload — the ninth CVE of the August 2026 hardening set, absent from the W34 weekly rollup enumeration (1)

2026-08-24 · view entry permalink →

NOTABLECVE-2026-20030 +8updateNATOA2

Cisco Crosswork and Secure Workload ship nine CVEs where each identifier stands for a whole class of bugs — six reachable unauthenticated, three at low privilege, and no workaround for any of them

UPDATE · originally covered 2026-W34 vulnerability status roll-up — seven flaws crossed into reported exploitation this week; six were catalogue listings against fixes that had existed for weeks or months, and the seventh went from out-of-band patch to exploitation in two days with no catalogue involved at all (2026-08-23)

Cisco published two hardening advisories out of internal security review on 2026-08-19 covering Crosswork — its network orchestration, planning and workflow platform — and Secure Workload, its workload microsegmentation product. Together they carry nine CVEs, five of them scored 10.0 and two more 9.9 (Cisco PSIRT, 2026-08-19, Cisco PSIRT, 2026-08-19). The number to read past is the score; the structure behind it is what changes a defender's options. Cisco states it grouped the issues by underlying weakness class and assigned one CVE identifier per grouping, and that each score represents the maximum potential severity of the single most impactful underlying bug within that class (Cisco PSIRT, 2026-08-19). One identifier can therefore stand for several distinct bugs, and no individual flaw is assessable from the advisory — the estate is triaged by release, not by finding. This pipeline recorded the identical construction in Cisco's August IOS XE hardening release, so it now reads as a settled disclosure practice on internally found bug batches rather than a one-off.

The authentication picture is more mixed than a list of tens implies, and the vendor's own vectors settle it. On Crosswork, CVE-2026-20030 (SQL injection), CVE-2026-20357 (missing authentication for a critical function) and CVE-2026-20358 (external control of a file path) all carry PR:N at 10.0, while CVE-2026-20359 (insufficiently protected credentials, 9.9) carries PR:L and therefore needs an existing low-privilege account. On Secure Workload, CVE-2026-20315 (improper access control) and CVE-2026-20317 (improper authentication) are PR:N at 10.0 and CVE-2026-20319 (a memory-buffer restriction failure, 7.5, availability impact only) is PR:N, while CVE-2026-20231 (injection, 9.9) and CVE-2026-20318 (improper input validation, 9.6) are both PR:L. NCSC-NL's independently published record for the Secure Workload cluster carries the same five vectors (NCSC-NL, 2026-08-21). Six unauthenticated and three at low privilege is not a reassuring split: low privilege on an orchestration or microsegmentation control plane means any read-only API consumer or delegated operator role is a sufficient foothold.

Cisco is explicit that it is not aware of any public announcements or malicious use of these vulnerabilities, and equally explicit that there are no workarounds that address them (Cisco PSIRT, 2026-08-19). Two further details change the work involved. Cisco credits the discovery to internal security testing "using existing testing processes as well as frontier AI models" (Cisco PSIRT, 2026-08-19) — the second Cisco hardening batch this month attributed partly to model-assisted internal review, which is a plausible explanation for why these arrive in classes rather than singly. And on Secure Workload SaaS, the fix is not fully server-side: Cisco states the cluster, agent and connector software all need upgrading and that for SaaS deployments it has upgraded the cluster while customers must still upgrade the agent and connector (Cisco PSIRT, 2026-08-19). A SaaS tenant that assumed its provider had closed this out has client-side work outstanding.

Because the advisories describe weakness classes rather than reachable interfaces, there is no honest per-flaw detection guidance to give and this entry does not invent any. What is available is exposure reduction and the audit trail these platforms already produce: establish which interfaces of each product answer from outside the management network at all, and treat the low-privilege accounts on both platforms as part of the blast radius rather than as a trust boundary — service accounts and delegated operator roles on an orchestration platform are the foothold three of these nine flaws need. Both products' own audit logging is the place a defender would see the consequence of exploitation rather than the attempt: configuration writes, policy changes and credential reads that do not correspond to a change request.

Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

The CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying vulnerability within that specific CWE category.

There are no workarounds that address these vulnerabilities.

The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.

The Cluster, Agent, and Connector software of Cisco Secure Workload need to be upgraded to resolve all of these vulnerabilities. For SaaS deployments, Cisco has upgraded the Cluster software, and customers need to upgrade only the Agent and Connector software.

Cisco PSIRT 2026-08-19

Builds on: 2026-08-08/cisco-ios-xe-august-2026-hardening-release-cwe-grouped-cves

vulnerability24 Aug 09:15Zmulti-sourceOpen finding ↗
Sources: Cisco PSIRT · NCSC-NL