CVE-2026-20359 PUBLISHED

Cisco Crosswork Security Hardening Release: August 2026

Assigner: cisco
Reserved: 08.10.2025 Published: 19.08.2026 Updated: 19.08.2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities trackled by CVE-2026-20359 are related to insufficiently protected credentials issues that are grouped under the Common Weakness Enumeration (CWE) CWE-522.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor Cisco
Product Cisco Crosswork Planning
Versions Default: unknown
  • Version 7.0.2 is affected
  • Version 7.1.0 is affected
  • Version 7.0.0 is affected
  • Version 7.0.4 is affected
  • Version 7.0.1 is affected
  • Version 7.0.3 is affected
  • Version 7.2.0 is affected
  • Version 7.1.1 is affected
  • Version 7.1.2 is affected

Exploits

The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.

References

Problem Types

  • Insufficiently Protected Credentials cwe