Release roundup
Cisco vulnerabilities, week 34 of 2026: critical Splunk, Crosswork and Secure Workload fixes lead 125 CVEs
Cisco week 34 of 2026 covers 125 CVEs: 12 critical, 42 high, 66 medium and 5 low. No CVE is listed in CISA KEV or marked exploited. Prioritise Crosswork Planning, Secure Workload, Splunk Enterprise embedded reports and Splunk MCP Server, then move through the remaining high-severity Splunk items.
The release at a glance
Cisco's week 34 of 2026 covers 125 CVEs across Splunk and Cisco products. The release contains 12 critical, 42 high, 66 medium and 5 low severity findings. No CVE in this set is listed in CISA KEV or known to be exploited. Splunk Enterprise accounts for 60 of the 125 CVEs, followed by Splunk SOAR with 15. The most urgent items sit in Cisco Crosswork Planning, Cisco Secure Workload, Splunk Enterprise and the Splunk MCP Server app, where several network-reachable critical flaws allow unauthenticated action or affect system integrity.
What matters most
These are the issues to review first; the entries below are covered by separate advisory pages on this site.
Cisco Crosswork Planning: CVE-2026-20030 is SQL injection (CWE-89) and CVE-2026-20357 is missing authentication for a critical function (CWE-306); both are rated CVSS 10, network-accessible and require no privileges. Cisco states that PSIRT is not aware of public announcements or malicious use.
Cisco Secure Workload: CVE-2026-20315 is improper access control (CWE-284) and CVE-2026-20317 is improper authentication (CWE-287); both are rated CVSS 10, network-accessible and require no privileges, with scope change. Cisco states the same: no known public announcements or malicious use.
Splunk Enterprise: CVE-2026-76310, CVE-2026-76311 and CVE-2026-76312 are improper access control flaws in embedded reports. An unauthenticated user with an embedded report token can download dispatch archives or recover session material, then access report-owner data and affect system integrity; where the owner holds the admin role, administrative actions are possible. Each is rated CVSS 9.4, network-accessible and requires no user interaction.
Splunk MCP Server app: CVE-2026-76404 is remote code execution through deserialisation of untrusted data (CWE-502) for a user who already holds the admin role; it is rated CVSS 9.1 and fixed in version 1.2.1.
Patch in this order
- Cisco Crosswork Planning: apply the August 2026 hardening release first. CVE-2026-20030, CVE-2026-20357, CVE-2026-20358 and CVE-2026-20359 are internally found issues in the same advisory; the first two are pre-authentication and network-accessible. The available advisory does not list a fixed version for Crosswork Planning, so confirm the patched release with Cisco.
- Cisco Secure Workload: apply the August 2026 hardening release next. CVE-2026-20315, CVE-2026-20317, CVE-2026-20231 and CVE-2026-20318 are in the hardening advisory; the first two require no privileges. The available advisory does not list a fixed version for Secure Workload, so confirm the patched release with Cisco.
- Splunk Enterprise: update to the fixed trains. For CVE-2026-76310 and CVE-2026-76311, the fixed versions are 10.4.2, 10.2.6, 10.0.9 and 9.4.14. For CVE-2026-76312, the fixed versions are 10.4.1, 10.2.6, 10.0.9 and 9.4.14. Treat embedded-report token exposure as an integrity and data-access issue.
- Splunk MCP Server app: update to 1.2.1 for CVE-2026-76404; this addresses an admin-role remote code execution path.
- Then move through the remaining high-severity items: there are 42 high CVEs in this release, mainly across Splunk Enterprise, Splunk SOAR, Splunk AI Toolkit, Splunk Connect for Kafka and Splunk Enterprise Security. Follow with the 66 medium and 5 low findings during your normal patch cycle.
Beyond the patch
Monthly Cisco weeks like this are manageable when the pre-authentication and access-control items are already mapped to exposed assets. Implementation & Assessment Services can test whether the Crosswork, Secure Workload and Splunk embedded-report paths are reachable and whether the fixes close the flaws, while Virtual CISO Services (vCISO) keeps the resulting patch order visible to leadership from one month to the next.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-20030 | Cisco Crosswork Planning | Critical 10.0 | Advisory → |
| CVE-2026-20357 | Cisco Crosswork Planning | Critical 10.0 | Advisory → |
| CVE-2026-20317 | Cisco Secure Workload | Critical 10.0 | Advisory → |
| CVE-2026-20358 | Cisco Crosswork Planning | Critical 10.0 | Advisory → |
| CVE-2026-20315 | Cisco Secure Workload | Critical 10.0 | Advisory → |
| CVE-2026-20231 | Cisco Secure Workload | Critical 9.9 | Advisory → |
| CVE-2026-20359 | Cisco Crosswork Planning | Critical 9.9 | Advisory → |
| CVE-2026-20318 | Cisco Secure Workload | Critical 9.6 | Advisory → |
| CVE-2026-76310 | Splunk Enterprise | Critical 9.4 | Advisory → |
| CVE-2026-76311 | Splunk Enterprise | Critical 9.4 | Advisory → |
| CVE-2026-76312 | Splunk Enterprise | Critical 9.4 | Advisory → |
| CVE-2026-76404 | Splunk MCP Server app | Critical 9.1 | Advisory → |
| CVE-2026-76313 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76314 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76315 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76316 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76317 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76319 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76335 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76350 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76395 | Splunk AI Toolkit | High 8.8 | |
| CVE-2026-76253 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76259 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76351 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76352 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76389 | Cisco Talos Intelligence for Enterprise Security Cloud | High 8.8 | |
| CVE-2026-76391 | Splunk AI Toolkit | High 8.3 | |
| CVE-2026-76394 | Splunk AI Toolkit | High 8.3 | |
| CVE-2026-76402 | Splunk Connect for Kafka | High 8.2 | |
| CVE-2026-76356 | Splunk SOAR | High 8.1 | |
| CVE-2026-76331 | Splunk Enterprise | High 8.1 | |
| CVE-2026-76338 | Splunk Enterprise | High 8.1 | |
| CVE-2026-76354 | Splunk Enterprise | High 8.1 | |
| CVE-2026-76387 | Splunk Enterprise Security | High 8.1 | |
| CVE-2026-76388 | Splunk Enterprise Security | High 8.1 | |
| CVE-2026-76397 | Splunk AI Toolkit | High 8.1 | |
| CVE-2026-76399 | Splunk AI Toolkit | High 8.1 | |
| CVE-2026-76344 | Splunk Enterprise | High 7.7 | |
| CVE-2026-76357 | Splunk SOAR | High 7.6 | |
| CVE-2026-76262 | Splunk Enterprise | High 7.5 |
Show all 125
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-76355 | Splunk Enterprise | High 7.5 | |
| CVE-2026-20319 | Cisco Secure Workload | High 7.5 | Advisory → |
| CVE-2026-20320 | Cisco BroadWorks | High 7.5 | |
| CVE-2026-76254 | Splunk Enterprise | High 7.5 | |
| CVE-2026-76396 | Splunk AI Toolkit | High 7.5 | |
| CVE-2026-76362 | Splunk SOAR | High 7.4 | |
| CVE-2026-76403 | Splunk Connect for Kafka | High 7.4 | |
| CVE-2026-76321 | Splunk Enterprise | High 7.3 | |
| CVE-2026-76325 | Splunk Enterprise | High 7.3 | |
| CVE-2026-76251 | Splunk Enterprise | High 7.1 | |
| CVE-2026-76330 | Splunk Enterprise | High 7.1 | |
| CVE-2026-76332 | Splunk Enterprise | High 7.1 | |
| CVE-2026-76333 | Splunk Enterprise | High 7.1 | |
| CVE-2026-76336 | Splunk Enterprise | High 7.1 | |
| CVE-2026-76252 | Splunk Enterprise | Medium 6.8 | |
| CVE-2026-76322 | Splunk Enterprise | Medium 6.7 | |
| CVE-2026-76328 | Splunk Enterprise | Medium 6.7 | |
| CVE-2026-76372 | Nmap Scanner | Medium 6.6 | |
| CVE-2026-76358 | Splunk SOAR | Medium 6.5 | |
| CVE-2026-76359 | Splunk SOAR | Medium 6.5 | |
| CVE-2026-20327 | Cisco Unified Intelligence Center | Medium 6.5 | |
| CVE-2026-76257 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76258 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76260 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76343 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76363 | Splunk SOAR | Medium 6.5 | |
| CVE-2026-76364 | Splunk SOAR | Medium 6.5 | |
| CVE-2026-76365 | Splunk SOAR | Medium 6.5 | |
| CVE-2026-76366 | Splunk SOAR | Medium 6.5 | |
| CVE-2026-76255 | Splunk Enterprise | Medium 6.4 | |
| CVE-2026-76323 | Splunk Enterprise | Medium 6.4 | |
| CVE-2026-76327 | Splunk Enterprise | Medium 6.4 | |
| CVE-2026-76329 | Splunk Enterprise | Medium 6.4 | |
| CVE-2026-76349 | Splunk Enterprise | Medium 6.4 | |
| CVE-2026-76334 | Splunk Enterprise | Medium 6.4 | |
| CVE-2026-20302 | Cisco RoomOS Software | Medium 6.1 | |
| CVE-2026-76345 | Splunk Enterprise | Medium 6.0 | |
| CVE-2026-76320 | Splunk Enterprise | Medium 5.9 | |
| CVE-2026-76393 | Splunk AI Toolkit | Medium 5.9 | |
| CVE-2026-76400 | Splunk Connect for Kafka | Medium 5.9 | |
| CVE-2026-76401 | Splunk Connect for Kafka | Medium 5.9 | |
| CVE-2026-76318 | Splunk Enterprise | Medium 5.7 | |
| CVE-2026-76324 | Splunk Enterprise | Medium 5.7 | |
| CVE-2026-76326 | Splunk Enterprise | Medium 5.7 | |
| CVE-2026-20232 | Cisco Industrial Ethernet Switches | Medium 5.4 | |
| CVE-2026-76263 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76339 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76341 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76342 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76346 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76347 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76353 | Splunk Enterprise | Medium 5.4 | |
| CVE-2026-76373 | AD LDAP app for Splunk SOAR | Medium 5.4 | |
| CVE-2026-76392 | Splunk AI Toolkit | Medium 5.4 | |
| CVE-2026-20177 | Cisco Industrial Ethernet Switches | Medium 5.3 | |
| CVE-2026-76261 | Splunk Enterprise | Medium 5.3 | |
| CVE-2026-76337 | Splunk Enterprise | Medium 5.3 | |
| CVE-2026-76340 | Splunk Enterprise | Medium 5.3 | |
| CVE-2026-76390 | Cisco Talos Intelligence for Enterprise Security Cloud | Medium 5.3 | |
| CVE-2026-20314 | Cisco Packaged Contact Center Enterprise | Medium 5.0 | |
| CVE-2026-76375 | AD LDAP app for Splunk SOAR | Medium 5.0 | |
| CVE-2026-76256 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76309 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76360 | Splunk SOAR | Medium 4.3 | |
| CVE-2026-76370 | Splunk SOAR | Medium 4.3 | |
| CVE-2026-76374 | AD LDAP app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76376 | AWS IAM app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76377 | Azure AD Graph app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76378 | Cisco Secure Malware Analytics app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76379 | Cisco Webex app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76380 | CrowdStrike OAuth API app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76381 | MS Graph for Active Directory app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76382 | Phantom app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76383 | RSA SecurID Authentication Manager app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76384 | Splunk Attack Analyzer Connector for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76386 | Zoom app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76398 | Splunk AI Toolkit | Medium 4.3 | |
| CVE-2026-76405 | Splunk On-Call (VictorOps) | Medium 4.3 | |
| CVE-2026-76385 | Venafi app for Splunk SOAR | Medium 4.3 | |
| CVE-2026-76367 | Splunk SOAR | Medium 4.0 | |
| CVE-2026-76348 | Splunk Enterprise | Low 3.8 | |
| CVE-2026-76361 | Splunk SOAR | Low 2.7 | |
| CVE-2026-76368 | Splunk SOAR | Low 2.7 | |
| CVE-2026-76369 | Splunk SOAR | Low 2.7 | |
| CVE-2026-76371 | FireAMP | Low 2.7 |
References
Vendor advisory
CVE
- CVE-2026-20030 — cve.org
- CVE-2026-20030 — NVD
- CVE-2026-20357 — cve.org
- CVE-2026-20357 — NVD
- CVE-2026-20317 — cve.org
- CVE-2026-20317 — NVD
- CVE-2026-20358 — cve.org
- CVE-2026-20358 — NVD
- CVE-2026-20315 — cve.org
- CVE-2026-20315 — NVD
- CVE-2026-20231 — cve.org
- CVE-2026-20231 — NVD
- CVE-2026-20359 — cve.org
- CVE-2026-20359 — NVD
- CVE-2026-20318 — cve.org
- CVE-2026-20318 — NVD
- CVE-2026-76310 — cve.org
- CVE-2026-76310 — NVD
- CVE-2026-76311 — cve.org
- CVE-2026-76311 — NVD
- CVE-2026-76312 — cve.org
- CVE-2026-76312 — NVD
- CVE-2026-76404 — cve.org
- CVE-2026-76404 — NVD