Skip to content

Release roundup

Cisco vulnerabilities, week 34 of 2026: critical Splunk, Crosswork and Secure Workload fixes lead 125 CVEs

Critical 10.0 Vendor: Cisco 125 CVEs in scope Published

Cisco week 34 of 2026 covers 125 CVEs: 12 critical, 42 high, 66 medium and 5 low. No CVE is listed in CISA KEV or marked exploited. Prioritise Crosswork Planning, Secure Workload, Splunk Enterprise embedded reports and Splunk MCP Server, then move through the remaining high-severity Splunk items.

The release at a glance

Cisco's week 34 of 2026 covers 125 CVEs across Splunk and Cisco products. The release contains 12 critical, 42 high, 66 medium and 5 low severity findings. No CVE in this set is listed in CISA KEV or known to be exploited. Splunk Enterprise accounts for 60 of the 125 CVEs, followed by Splunk SOAR with 15. The most urgent items sit in Cisco Crosswork Planning, Cisco Secure Workload, Splunk Enterprise and the Splunk MCP Server app, where several network-reachable critical flaws allow unauthenticated action or affect system integrity.

What matters most

These are the issues to review first; the entries below are covered by separate advisory pages on this site.

Cisco Crosswork Planning: CVE-2026-20030 is SQL injection (CWE-89) and CVE-2026-20357 is missing authentication for a critical function (CWE-306); both are rated CVSS 10, network-accessible and require no privileges. Cisco states that PSIRT is not aware of public announcements or malicious use.

Cisco Secure Workload: CVE-2026-20315 is improper access control (CWE-284) and CVE-2026-20317 is improper authentication (CWE-287); both are rated CVSS 10, network-accessible and require no privileges, with scope change. Cisco states the same: no known public announcements or malicious use.

Splunk Enterprise: CVE-2026-76310, CVE-2026-76311 and CVE-2026-76312 are improper access control flaws in embedded reports. An unauthenticated user with an embedded report token can download dispatch archives or recover session material, then access report-owner data and affect system integrity; where the owner holds the admin role, administrative actions are possible. Each is rated CVSS 9.4, network-accessible and requires no user interaction.

Splunk MCP Server app: CVE-2026-76404 is remote code execution through deserialisation of untrusted data (CWE-502) for a user who already holds the admin role; it is rated CVSS 9.1 and fixed in version 1.2.1.

Patch in this order

  1. Cisco Crosswork Planning: apply the August 2026 hardening release first. CVE-2026-20030, CVE-2026-20357, CVE-2026-20358 and CVE-2026-20359 are internally found issues in the same advisory; the first two are pre-authentication and network-accessible. The available advisory does not list a fixed version for Crosswork Planning, so confirm the patched release with Cisco.
  2. Cisco Secure Workload: apply the August 2026 hardening release next. CVE-2026-20315, CVE-2026-20317, CVE-2026-20231 and CVE-2026-20318 are in the hardening advisory; the first two require no privileges. The available advisory does not list a fixed version for Secure Workload, so confirm the patched release with Cisco.
  3. Splunk Enterprise: update to the fixed trains. For CVE-2026-76310 and CVE-2026-76311, the fixed versions are 10.4.2, 10.2.6, 10.0.9 and 9.4.14. For CVE-2026-76312, the fixed versions are 10.4.1, 10.2.6, 10.0.9 and 9.4.14. Treat embedded-report token exposure as an integrity and data-access issue.
  4. Splunk MCP Server app: update to 1.2.1 for CVE-2026-76404; this addresses an admin-role remote code execution path.
  5. Then move through the remaining high-severity items: there are 42 high CVEs in this release, mainly across Splunk Enterprise, Splunk SOAR, Splunk AI Toolkit, Splunk Connect for Kafka and Splunk Enterprise Security. Follow with the 66 medium and 5 low findings during your normal patch cycle.

Beyond the patch

Monthly Cisco weeks like this are manageable when the pre-authentication and access-control items are already mapped to exposed assets. Implementation & Assessment Services can test whether the Crosswork, Secure Workload and Splunk embedded-report paths are reachable and whether the fixes close the flaws, while Virtual CISO Services (vCISO) keeps the resulting patch order visible to leadership from one month to the next.

Every CVE in this release

CVEProductSeverity
CVE-2026-20030Cisco Crosswork PlanningCritical 10.0Advisory →
CVE-2026-20357Cisco Crosswork PlanningCritical 10.0Advisory →
CVE-2026-20317Cisco Secure WorkloadCritical 10.0Advisory →
CVE-2026-20358Cisco Crosswork PlanningCritical 10.0Advisory →
CVE-2026-20315Cisco Secure WorkloadCritical 10.0Advisory →
CVE-2026-20231Cisco Secure WorkloadCritical 9.9Advisory →
CVE-2026-20359Cisco Crosswork PlanningCritical 9.9Advisory →
CVE-2026-20318Cisco Secure WorkloadCritical 9.6Advisory →
CVE-2026-76310Splunk EnterpriseCritical 9.4Advisory →
CVE-2026-76311Splunk EnterpriseCritical 9.4Advisory →
CVE-2026-76312Splunk EnterpriseCritical 9.4Advisory →
CVE-2026-76404Splunk MCP Server appCritical 9.1Advisory →
CVE-2026-76313Splunk EnterpriseHigh 8.8
CVE-2026-76314Splunk EnterpriseHigh 8.8
CVE-2026-76315Splunk EnterpriseHigh 8.8
CVE-2026-76316Splunk EnterpriseHigh 8.8
CVE-2026-76317Splunk EnterpriseHigh 8.8
CVE-2026-76319Splunk EnterpriseHigh 8.8
CVE-2026-76335Splunk EnterpriseHigh 8.8
CVE-2026-76350Splunk EnterpriseHigh 8.8
CVE-2026-76395Splunk AI ToolkitHigh 8.8
CVE-2026-76253Splunk EnterpriseHigh 8.8
CVE-2026-76259Splunk EnterpriseHigh 8.8
CVE-2026-76351Splunk EnterpriseHigh 8.8
CVE-2026-76352Splunk EnterpriseHigh 8.8
CVE-2026-76389Cisco Talos Intelligence for Enterprise Security CloudHigh 8.8
CVE-2026-76391Splunk AI ToolkitHigh 8.3
CVE-2026-76394Splunk AI ToolkitHigh 8.3
CVE-2026-76402Splunk Connect for KafkaHigh 8.2
CVE-2026-76356Splunk SOARHigh 8.1
CVE-2026-76331Splunk EnterpriseHigh 8.1
CVE-2026-76338Splunk EnterpriseHigh 8.1
CVE-2026-76354Splunk EnterpriseHigh 8.1
CVE-2026-76387Splunk Enterprise SecurityHigh 8.1
CVE-2026-76388Splunk Enterprise SecurityHigh 8.1
CVE-2026-76397Splunk AI ToolkitHigh 8.1
CVE-2026-76399Splunk AI ToolkitHigh 8.1
CVE-2026-76344Splunk EnterpriseHigh 7.7
CVE-2026-76357Splunk SOARHigh 7.6
CVE-2026-76262Splunk EnterpriseHigh 7.5
Show all 125
CVEProductSeverity
CVE-2026-76355Splunk EnterpriseHigh 7.5
CVE-2026-20319Cisco Secure WorkloadHigh 7.5Advisory →
CVE-2026-20320Cisco BroadWorksHigh 7.5
CVE-2026-76254Splunk EnterpriseHigh 7.5
CVE-2026-76396Splunk AI ToolkitHigh 7.5
CVE-2026-76362Splunk SOARHigh 7.4
CVE-2026-76403Splunk Connect for KafkaHigh 7.4
CVE-2026-76321Splunk EnterpriseHigh 7.3
CVE-2026-76325Splunk EnterpriseHigh 7.3
CVE-2026-76251Splunk EnterpriseHigh 7.1
CVE-2026-76330Splunk EnterpriseHigh 7.1
CVE-2026-76332Splunk EnterpriseHigh 7.1
CVE-2026-76333Splunk EnterpriseHigh 7.1
CVE-2026-76336Splunk EnterpriseHigh 7.1
CVE-2026-76252Splunk EnterpriseMedium 6.8
CVE-2026-76322Splunk EnterpriseMedium 6.7
CVE-2026-76328Splunk EnterpriseMedium 6.7
CVE-2026-76372Nmap ScannerMedium 6.6
CVE-2026-76358Splunk SOARMedium 6.5
CVE-2026-76359Splunk SOARMedium 6.5
CVE-2026-20327Cisco Unified Intelligence CenterMedium 6.5
CVE-2026-76257Splunk EnterpriseMedium 6.5
CVE-2026-76258Splunk EnterpriseMedium 6.5
CVE-2026-76260Splunk EnterpriseMedium 6.5
CVE-2026-76343Splunk EnterpriseMedium 6.5
CVE-2026-76363Splunk SOARMedium 6.5
CVE-2026-76364Splunk SOARMedium 6.5
CVE-2026-76365Splunk SOARMedium 6.5
CVE-2026-76366Splunk SOARMedium 6.5
CVE-2026-76255Splunk EnterpriseMedium 6.4
CVE-2026-76323Splunk EnterpriseMedium 6.4
CVE-2026-76327Splunk EnterpriseMedium 6.4
CVE-2026-76329Splunk EnterpriseMedium 6.4
CVE-2026-76349Splunk EnterpriseMedium 6.4
CVE-2026-76334Splunk EnterpriseMedium 6.4
CVE-2026-20302Cisco RoomOS SoftwareMedium 6.1
CVE-2026-76345Splunk EnterpriseMedium 6.0
CVE-2026-76320Splunk EnterpriseMedium 5.9
CVE-2026-76393Splunk AI ToolkitMedium 5.9
CVE-2026-76400Splunk Connect for KafkaMedium 5.9
CVE-2026-76401Splunk Connect for KafkaMedium 5.9
CVE-2026-76318Splunk EnterpriseMedium 5.7
CVE-2026-76324Splunk EnterpriseMedium 5.7
CVE-2026-76326Splunk EnterpriseMedium 5.7
CVE-2026-20232Cisco Industrial Ethernet SwitchesMedium 5.4
CVE-2026-76263Splunk EnterpriseMedium 5.4
CVE-2026-76339Splunk EnterpriseMedium 5.4
CVE-2026-76341Splunk EnterpriseMedium 5.4
CVE-2026-76342Splunk EnterpriseMedium 5.4
CVE-2026-76346Splunk EnterpriseMedium 5.4
CVE-2026-76347Splunk EnterpriseMedium 5.4
CVE-2026-76353Splunk EnterpriseMedium 5.4
CVE-2026-76373AD LDAP app for Splunk SOARMedium 5.4
CVE-2026-76392Splunk AI ToolkitMedium 5.4
CVE-2026-20177Cisco Industrial Ethernet SwitchesMedium 5.3
CVE-2026-76261Splunk EnterpriseMedium 5.3
CVE-2026-76337Splunk EnterpriseMedium 5.3
CVE-2026-76340Splunk EnterpriseMedium 5.3
CVE-2026-76390Cisco Talos Intelligence for Enterprise Security CloudMedium 5.3
CVE-2026-20314Cisco Packaged Contact Center EnterpriseMedium 5.0
CVE-2026-76375AD LDAP app for Splunk SOARMedium 5.0
CVE-2026-76256Splunk EnterpriseMedium 4.3
CVE-2026-76309Splunk EnterpriseMedium 4.3
CVE-2026-76360Splunk SOARMedium 4.3
CVE-2026-76370Splunk SOARMedium 4.3
CVE-2026-76374AD LDAP app for Splunk SOARMedium 4.3
CVE-2026-76376AWS IAM app for Splunk SOARMedium 4.3
CVE-2026-76377Azure AD Graph app for Splunk SOARMedium 4.3
CVE-2026-76378Cisco Secure Malware Analytics app for Splunk SOARMedium 4.3
CVE-2026-76379Cisco Webex app for Splunk SOARMedium 4.3
CVE-2026-76380CrowdStrike OAuth API app for Splunk SOARMedium 4.3
CVE-2026-76381MS Graph for Active Directory app for Splunk SOARMedium 4.3
CVE-2026-76382Phantom app for Splunk SOARMedium 4.3
CVE-2026-76383RSA SecurID Authentication Manager app for Splunk SOARMedium 4.3
CVE-2026-76384Splunk Attack Analyzer Connector for Splunk SOARMedium 4.3
CVE-2026-76386Zoom app for Splunk SOARMedium 4.3
CVE-2026-76398Splunk AI ToolkitMedium 4.3
CVE-2026-76405Splunk On-Call (VictorOps)Medium 4.3
CVE-2026-76385Venafi app for Splunk SOARMedium 4.3
CVE-2026-76367Splunk SOARMedium 4.0
CVE-2026-76348Splunk EnterpriseLow 3.8
CVE-2026-76361Splunk SOARLow 2.7
CVE-2026-76368Splunk SOARLow 2.7
CVE-2026-76369Splunk SOARLow 2.7
CVE-2026-76371FireAMPLow 2.7

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.