CVE-2026-20030Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements used in a SQL command issues that are grouped under the Common Weakness Enumeration (CWE) CWE-89.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-08-20); latest day: 1
  • 11 total mentions across 6 days

Deep dive

Activity timeline11 mentions / 6d
01345Mentions · 2026-08-19: 1Mentions · 2026-08-20: 5Mentions · 2026-08-21: 1Mentions · 2026-08-23: 1Mentions · 2026-08-24: 2Mentions · 2026-08-28: 1PoC Mentioned / Linked · 2026-08-20: 1Active Exploitation · 2026-08-24: 1Patch / Workaround · 2026-08-20: 2Patch / Workaround · 2026-08-24: 2Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-24: 208-1908-2008-2108-2308-2408-28
Signal classification4 categories
Disclosure
436.4%
Patch
436.4%
General
218.2%
PoC
19.1%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-205
General2Patch2PoC1
2026-08-211
Disclosure1
2026-08-231
Disclosure1
2026-08-242
Patch2
2026-08-281
Disclosure1
Full discourse11 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix. #Cisco #CVE #SQLInjection #Crosswork #BroadWorks #XXE #Vulnerability #InfoSec https://securityonline.info/cisco-crosswork-cve-2026-20030/

    Post summary

    The post announces that Cisco has released patches for a high‑severity SQL injection flaw (CVE‑2026‑20030) in Crosswork and an XXE bug (CVE‑2026‑20320) in BroadWorks.

    41021459
    13.0K followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:週末のセキュリティ関連ニュース/記事】 <脆弱性> ・シスコ、CrossworkとSecure Workloadに存在する脆弱性9件を修正 うち5件はCVSS 10.0(CVE-2026-20030、CVE-2026-20357他) https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html ・MLFlowの重大な欠陥が悪用される 月間3,000万回ダウンロードされるAIプラットフォーム(CVE-2026-64849) https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/ ・米CISA、悪用されているTrueConfサーバーの脆弱性へのパッチ適用を連邦政府機関に命じる(CVE-2026-72529、CVE-2026-72530) https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/ ・ライブラリ「isolated-vm」の重大な脆弱性により、ホスト上でRCEが可能に https://www.securityweek.com/critical-isolated-vm-vulnerability-leads-to-rce-on-host/ ・マイクロソフト、最大深刻度の脆弱性を複数修正 コード実行や権限昇格を許す恐れ(CVE-2026-69836、CVE-2026-65816他) https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/ <マルウェア・その他脅威> ・Androidマルウェア「ToxicPanda」 VPN権限を悪用してGoogle Playをブロック https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/ ・AndroidマルウェアがFirebaseを悪用し、ICICI・SBI・Axisなどインド各銀行になりすまし 政府の無効化通知で明らかに https://ministryofcyberaffairs.com/news/indian-banks-including-icici-sbi-axis-impersonated-by-android-malware-using-firebase-government-blocking-notices-show-48362865-20a2-4665-9df6-09386ad3e106 ・Microsoft Teams悪用のフィッシング攻撃で新マルウェア「SynkLoader」が拡散される https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/ ・車のヘッドユニット狙うマルウェアが発見される https://securelist.com/android-head-unit-malware/121106/ ・FTPバナーを悪用し、新種のWindows向けマルウェアが配布される https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/ ・人気AIブランド装い、マルウェアを拡散する攻撃が複数確認される https://www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/ ・偽マネーロンダリング対策サイト、ユーザーを騙して暗号通貨の取引を承認させる https://hackread.com/fake-aml-sites-crypto-approving-malicious-transactions/ ・1万ドルで販売されるフィッシングキット、パスキー登録で乗っ取ったアカウントへの永続的なアクセスが可能と主張 https://www.theregister.com/cyber-crime/2026/08/21/10k-phishing-kit-claims-it-can-plant-rogue-passkeys-for-persistent-access-to-pwned-accounts/5291006 ・トロイの木馬化された14件のnpmパッケージ、AI活用するC2機能備えたLinux向けバックドアRedC2 4.0を配布 https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html ・バンキング型トロイの木馬Manic・Grandoreiro・ToxicPanda 2.0の詳細 https://www.securityweek.com/banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight/ <データ侵害/サイバー犯罪> ・トロント小児病院のデータ侵害で職員と求職者の情報が流出 https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/ ・米PE投資会社アポロがデータ侵害の発生を認める 金融大手狙ったハッキング攻撃が相次ぐさなか https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/ <AI関連> ・暗号化されたプロンプトでGrokやGeminiの安全対策が破られる恐れ https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-and-gemini/ ・自システムへの模擬攻撃にAIを活用しなければ、その隙を攻撃者に突かれることに https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-attack-your-own-systems-your-adversaries-will/5291346 ・暴走したAIモデルを制御する方法、最先端の研究所も依然明らかにせず https://techcrunch.com/2026/08/22/frontier-ai-labs-still-wont-say-how-theyd-contain-a-rogue-model/ ・OWASP、新セキュリティ指針でAIスキルの主要なリスクを指摘 https://www.darkreading.com/application-security/owasp-flags-top-ai-skill-risks-security-blueprint ・OpenAI、制御機能を複数追加 本来ならすでに実装されているべき? https://www.darkreading.com/application-security/openai-adds-controls-already ・AIのサイバー攻撃能力をベンチマークテストで順位付け https://www.aikido.dev/blog/ai-model-benchmarks-aug-21-2026 ・詳細不明のAIモデル「Ox Alpha」無料版、コーディングベンチマークでトップに https://startupfortune.com/a-mystery-model-called-ox-alpha-just-topped-coding-benchmarks-for-free/ ・AI企業が書籍を廃棄しているとして、複数の活動団体が米連邦取引委員会に苦情 https://www.theregister.com/ai-and-ml/2026/08/21/ai-companies-are-burning-books-advocates-complain-to-ftc/5291299 <サイバー戦/APT/国家型アクター/地政学関連> ・イラン系ハッカーの攻撃で英発電所が4日間停止 米水道施設への攻撃と同時期に発生 https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html ・米政府の研究所が中国製LiDARにおけるセキュリティ上の欠陥を調査 https://techcrunch.com/2026/08/21/us-government-lab-is-probing-chinese-lidar-for-security-vulnerabilities/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・Uberに8億2,500万ユーロの制裁金 ドライバーのアカウント自動停止をめぐるGDPR違反で https://techcrunch.com/2026/08/23/uber-faces-fine-of-nearly-1b-over-automated-driver-suspensions/ ・インド政府、銀行詐欺に関連するGoogle Firebaseアカウントの削除を命じる https://www.reuters.com/world/india/india-orders-removal-google-firebase-accounts-after-spotting-scam-pattern-2026-08-21/ <プライバシー> ・アリババ、ユーザー追跡目的でWebAudio使いフィンガープリンティングを作成 https://cyberinsider.com/alibaba-spotted-using-webaudio-fingerprinting-for-user-tracking/ ・TikTok、児童のプライバシー侵害訴訟で和解金4億米ドルの支払いに合意 https://techcrunch.com/2026/08/21/tiktok-reaches-400m-settlement-over-childrens-privacy-lawsuit/ ・米上院議員、法執行機関のハッキングツール使用法について見直すよう監査機関に要請 https://techcrunch.com/2026/08/21/senator-asks-us-federal-watchdog-to-review-how-feds-use-hacking-tools/ <リサーチ/攻撃手法/TTP> ・脅威インテリジェンス:Xユーザー狙ったDMCA関連の認証情報フィッシング https://ministryofcyberaffairs.com/news/threat-intelligence-dmca-themed-credential-phishing-targeting-x-twitter-users-cf7df827-ab3b-4ffc-a556-1c293a83d814 ・Windowsの名前付きパイプに危機 プロセス間通信を保全する方法 https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/ ・漏洩状態のAWSキー数百件、悪用されれば企業アカウントの完全な乗っ取りが可能に https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/ ・Microsoft Defenderの正規ドライバー、起動時にセキュリティソフトを削除する攻撃ツールとして悪用される可能性 https://thehackernews.com/2026/08/microsoft-defenders-own-driver-can-be.html <その他> ・「EchoBench」で自律型ペネトレーションテストツールを評価 人間による実測値を基準としたベンチマーク https://www.netspi.com/blog/technical-blog/ai-ml-pentesting/introducing-echobench-a-human-calibrated-benchmark-for-autonomous-pentesting/

    Post summary

    The text reports recent CVE notifications, notes that several vulnerabilities are currently being exploited, and documents that patches or mitigations are available for multiple products.

    010223.6K
    1.3K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na několik zranitelností v Cisco Crosswork, CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20359. V produktech Cisco Crosswork Data Gateway, Crosswork Network Controller a Crosswork Planning byly identifikovány čtyři kritické zranitelnosti, které se projevují bez ohledu na konfiguraci zařízení. Jedná se o SQL Injection (CVE-2026-20030, CVSS 10.0), chybějící autentizaci pro kritickou funkci (CVE-2026-20357, CVSS 10.0), možnost externí kontroly souborového systému (CVE-2026-20358, CVSS 10.0) a nedostatečně chráněné přihlašovací údaje (CVE-2026-20359, CVSS 9.9). Úspěšné zneužití může útočníkovi umožnit neoprávněný přístup ke kritickým funkcím systému, manipulaci s daty, přístup k souborovému systému, kompromitaci přihlašovacích údajů a potenciálně úplné ovládnutí postiženého prostředí. Zranitelnosti ovlivňují Cisco Crosswork Release 7.2.1 a starší verze. 📌Doporučujeme aktualizovat na verzi 7.2.1-SP.

    Post summary

    The text announces four critical CVEs affecting Cisco Crosswork versions 7.2.1 and earlier, details their nature, and highlights a patch update to 7.2.1‑SP.

    11010850
    4.3K followersView on X
  • キタきつね@foxbook
    Disclosure

    Cisco Crossworkに最大CVSS 10.0の極めて深刻なSQLインジェクションの脆弱性(CVE-2026-20030等)が発覚 CVE-2026-20030: Cisco Crosswork SQL Command Injection Scores CVSS 10.0 #DailyCyberSecurity (Aug 20) https://securityonline.info/cisco-crosswork-cve-2026-20030/

    Post summary

    The text announces the discovery of a critical (CVSS 10.0) SQL injection CVE-2026-20030 in Cisco Crosswork, without providing details on PoC, exploitation, or patches.

    00021393
    5.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🛡️ Cisco Crosswork and WordPress: Unexpected Critical Additions Cisco disclosed two perfect-10 vulnerabilities in its Crosswork network automation platform — CVE-2026-20357 and CVE-2026-20030 — as part of a proactive security hardening…

    Post summary

    Cisco has announced two new critical vulnerabilities in its Crosswork platform, but no further technical or exploit details are provided.

    1000081
    80 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-20030 [HIGH PRIORITY] #Cisco Crosswork Security Hardening Release: August 2026 🔗 https://exploitgrid.net/cve/CVE-2026-20030

    Post summary

    The post announces CVE-2026-20030 as high priority and links to an exploit resource, but provides no details on the vulnerability, exploitation, or mitigation.

    1000039
    37 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-20030 CVE-2026-20315 CVE-2026-20317 CVE-2026-20357 CVE-2026-20358 ..🧵👇

    Post summary

    The digest lists five CVE identifiers without accompanying details, suggesting a general announcement of vulnerabilities.

    1000033
    37 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🗄️ Cisco Crosswork hit with a CVSS 10 SQL Injection — unauthenticated, network-exploitable, full system compromise possible. CVE-2026-20030 needs your attention now. #cybersecurity #cisco #ciso #cto #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-20030?utm_campaign=x https://t.co/rSGT3ER1Fy

    Post summary

    The tweet announces a new CVE (CVE-2026-20030) with a CVSS 10 SQL Injection in Cisco Crosswork, highlighting its severity but providing no evidence of exploitation, patches, or PoC.

    00000159
    878 followersView on X
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-20030 参照元(ベンダー等): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh, https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification

    Post summary

    The post merely lists the NVD entry and vendor advisory URLs for CVE‑2026‑20030 without providing concrete technical details, exploit information, or patch guidance.

    0000046
    26 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Cisco CrossworkでCVSSスコア10を含む重大(Critical)な脆弱性が多数修正。Data Gateway、Network Controller、Planning各プラットフォームに影響。修正有、緩和策無。 https://securityonline.info/cisco-crosswork-cve-2026-20030/

    Post summary

    Multiple critical (CVSS 10) vulnerabilities were found in Cisco Crosswork; patches have been released, but no mitigations are advised.

    00000597
    7.7K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-20030 Cisco Crosswork Security Hardening Release: August 2026 CVSS 10.0 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-20030 #Cisco #CyberSecurity #InfoSec

    Post summary

    The tweet announces a new critical vulnerability (CVE‑2026‑20030) with a CVSS score of 10.0, noting that no patch is currently available and directing readers to a full analysis.

    0000045
    82 followersView on X

Explore more