[source: 1]Date: 2026/08/24
【Vulnerability Alert】4 Critical Security Vulnerabilities Found in Cisco Crosswork
Description:
Forwarded from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC) Security Information Alert TWCERTCC-200-202608-00000016
The Cisco Crosswork development team identified multiple security vulnerabilities during internal security reviews and has completed patches for them. Currently, there is no evidence indicating that these vulnerabilities are being actively exploited. To assist customers in deploying security updates in a timely manner and to streamline the vulnerability disclosure process, Cisco has publicly released relevant vulnerability information and remediation advice.
CVE-2026-20030 (CVSS: 10.0) is an Improper Neutralization of Special Elements used in an SQL Command vulnerability; CVE-2026-20357 (CVSS: 10.0) is a Missing Authentication for Critical Function vulnerability; CVE-2026-20358 (CVSS: 10.0) is an External Control of File Name or Path vulnerability; CVE-2026-20359 (CVSS: 9.8) is an Insufficient Credential Protection vulnerability.
Affected Systems:
Recommendations:
Reference:
-
Computer and Communication Center
Network System Division