CVE-2026-20359
Cisco Crosswork Security Hardening Release: August 2026
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and Moreen·The Hacker News·
- Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0en·The Hacker News· Patch Crosswork Data Gateway web-app
- Cisco Patches Critical Crosswork, Secure Workload Vulnerabilitiesen-us·SecurityWeek· Patch Crosswork rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20359 and every CVE in our database. Create a free account — no credit card required.
Create Free Account