Emergency security maintenance updates have been published for enterprise network automation and workload protection platforms to resolve nine severe vulnerabilities, five of which carry maximum severity ratings. The flaws permit unauthenticated remote network actors to execute arbitrary system code with root privileges.
The vulnerabilities affect Cisco Crosswork Network Controller and Cisco Secure Workload architectures. The most critical issues, including SQL injection CVE-2026-20030, authentication bypass CVE-2026-20357, and external file system control CVE-2026-20358, each receive a CVSS score of 10.0. An unauthenticated attacker transmitting malformed API calls to exposed controller interfaces can bypass credential validation, execute raw database commands, overwrite arbitrary system files, and gain complete administrative control over the host appliance.
Subverting central network automation and workload segmentation controllers destroys logical boundaries across enterprise networks. Because Crosswork and Secure Workload platforms govern network routing policies, zero-trust microsegmentation rules, and device telemetry, an administrative takeover allows threat actors to disable security monitoring, modify network access controls, and pivot horizontally across connected cloud and on-premises subnets.
– Upgrade Cisco Crosswork Network Controller and Secure Workload installations to patched maintenance releases immediately.
– Restrict management interface accessibility by isolating controller API endpoints on dedicated, non-routable management VLANs.
– Inspect application audit logs for unauthorized SQL command strings or unverified file modification requests.
– Audit active API keys and administrative user registries across network automation appliances.
Network orchestration security relies on continuous API authentication verification and strict interface isolation to ensure central network controllers remain completely protected from unauthenticated remote code execution. #CodeDefence #Cisco #Crosswork #SecureWorkload #RCE #SQLi #AuthBypass #NetworkSecurity
/
