stagirus

announcement-check

Cisco's Bug Severity Warning Reads Like Olympic Gymnastics Scores: 10, 10, 9.9, 9.6, 7.5

Cisco disclosed nine critical-to-high severity flaws across Secure Workload, Crosswork, and BroadWorks on August 19, 2026, none exploited yet — and credits its own AI-assisted testing for catching them first.

Cisco published eight security advisories on August 19, 2026, and the top of the list reads like a scoreboard from an event nobody wants to win: two flaws scored a perfect 10.0, one hit 9.9, another 9.6, and a fifth landed at 7.5. All five belong to Cisco Secure Workload, the company's workload-protection platform, and the warning applies whether customers run it on-premises or as SaaS — there is no configuration that dodges the exposure.

The Secure Workload advisory lists five CVEs. CVE-2026-20315 (improper access control) and CVE-2026-20317 (improper authentication) each scored 10.0. CVE-2026-20231, a command and OS injection flaw, scored 9.9. CVE-2026-20318, a path-traversal bug from improper input validation, scored 9.6. CVE-2026-20319, a buffer overflow, is the 7.5 — still serious, just the runt of this particular litter. Cisco's fix is version 3.10.9.1 or 4.0.4.16 and later, and the advisory states plainly that no workarounds exist.

A second, separate advisory hit Cisco's Crosswork network-automation suite (Data Gateway, Network Controller, and Planning) with four more CVEs, three of them also scored 10.0: CVE-2026-20030 (SQL injection), CVE-2026-20357 (missing authentication), and CVE-2026-20358 (file system control), plus CVE-2026-20359 (weak credential protection) at 9.9. Cisco's fix there is version 7.2.1-SP, again with no mitigating workaround. A separate high-severity XXE injection bug in Cisco BroadWorks scored 7.5, and the batch closes with four medium-severity issues spanning Unified Intelligence Center, RoomOS, an Industrial Ethernet switch, and Contact Center.

None of the nine critical or high-severity bugs across Secure Workload, Crosswork, and BroadWorks is known to have been exploited. That is worth pausing on, because it breaks from Cisco's recent pattern: over the past year the company has repeatedly found out about its own zero-days from the attackers exploiting them, including state-sponsored intrusions through ASA and FTD appliances and an actively exploited IOS XE remote-code-execution bug this past April. This time, Cisco says it found the Secure Workload and Crosswork flaws itself, through internal security testing that it credits partly to "frontier AI models."

That detail connects to a shift in how Cisco discloses vulnerabilities. Starting in July 2026, the company moved to a twice-monthly scheduled disclosure cadence with seven days' advance notice, a change it explained in a blog post titled "Strengthening the Foundation" as a direct response to AI-accelerated vulnerability discovery outpacing the old ad-hoc disclose-and-patch rhythm. The company has attached names to the effort — Project Glasswing and Project Daybreak — aimed at machine-speed bug-hunting and remediation, alongside an open-source Foundry Security Spec meant to let other organizations replicate the approach.

There's a wrinkle in leaning on AI to find bugs faster: Cisco's own researchers have published work showing the AI models doing the hunting are themselves easy to break. A Cisco study covered by Help Net Security in May 2026 found frontier models caved to multi-turn jailbreak attacks up to 88% of the time across roughly 7,000 attempts. Cisco is using AI to secure its products while simultaneously documenting how fragile that same class of AI system is under sustained pressure — a tension the company has not resolved so much as scheduled around, one advisory batch every two weeks.