Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Crosswork Security Hardening Release: August 2026

Cisco has identified multiple security weaknesses in its Crosswork product line after an internal review. These issues could allow attackers to control software functionality, access protected credentials, execute harmful database commands, or manipulate files improperly. Cisco released software updates to fix these problems, and no workaround solutions are available. Users are advised to upgrade their software promptly to protect their systems.

Published 21/8/2026, 4:54:40 pmVerified 31/8/2026, 8:48:26 pmRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco has identified multiple security weaknesses in its Crosswork product line after an internal review. These issues could allow attackers to control software functionality, access protected credentials, execute harmful database commands, or manipulate files improperly. Cisco released software updates to fix these problems, and no workaround solutions are available. Users are advised to upgrade their software promptly to protect their systems.

Technical explanation

How the issue affects the environment

Cisco Crosswork versions prior to the specified fixed releases contain critical vulnerabilities including CWE-89 (SQL Injection), CWE-306 (Missing Authentication for Critical Function), CWE-73 (External Control of File System), and CWE-522 (Insufficiently Protected Credentials). These weaknesses could lead to remote code execution, unauthorized access, and compromise of confidentiality, integrity, and availability. Each vulnerability grouping was assigned a CVE identifier with max CVSS scores of 10.0 or 9.9, indicating extreme severity. Cisco has released fixed software versions—such as 7.2.1-SP and 2.1.1-SP—that address these vulnerabilities. No workarounds exist; upgrading is required for remediation.

Operational impact

Why teams should care

If exploited, these vulnerabilities could result in full compromise of networks running affected Cisco Crosswork products, allowing attackers to manipulate critical network management functions, steal credentials, corrupt data, or disrupt service availability. This presents significant operational, financial, and reputational risk for organizations relying on these systems. Proactive patching is critical to mitigate this risk.

Immediate action

Cisco strongly recommends customers upgrade affected Crosswork products to the fixed software releases indicated: 7.2.1-SP for Data Gateway, Network Controller, and Planning; 2.1.1-SP for Workflow Manager. These versions fully remediate the known vulnerabilities identified in this advisory. No alternate mitigations or workarounds are available.

Affected and fixed releases

Affected versionsCrosswork Data Gateway 7.2.1 and earlier, Crosswork Network Controller 7.2.1 and earlier, Crosswork Planning 7.2.1 and earlier, Crosswork Workflow Manager 2.1.1 and earlier
Fixed versionsCrosswork Data Gateway 7.2.1-SP, Crosswork Network Controller 7.2.1-SP, Crosswork Planning 7.2.1-SP, Crosswork Workflow Manager 2.1.1-SP

Temporary risk reduction

Cisco has stated that there are no workarounds available to address these vulnerabilities. Full remediation requires upgrading to the provided fixed software releases.

Evidence and validation checklist

  • Cisco internal security review found multiple vulnerabilities
  • Vulnerabilities grouped by CWE and assigned CVE IDs
  • CVSS scores up to 10.0 for critical vulnerabilities
  • Affected software versions and fixed releases clearly identified
  • No workarounds available
  • Official advisory published by Cisco PSIRT
  • No known exploitation reported

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source