CVE-2026-20357 rates CVSS 10, but the score masks a more dangerous reality: Cisco Crosswork shipped multiple critical functions without any authentication mechanism at all. This isn't a bypass or a weak credential — it's the categorical absence of access controls on functions that a network management platform uses to touch infrastructure across your environment. That distinction matters for your prioritization.

The grouped disclosure is your first operational problem. This single CVE bundles an unspecified number of unauthenticated functions, which means you cannot determine which specific endpoints, APIs, or management interfaces lack authentication. Attackers will reverse-engineer the patch and build an exact inventory. You get advisory language. This asymmetry extends your effective exposure window well beyond patch deployment, because you cannot verify coverage — you can only patch comprehensively and hope you caught everything.

The cascade risk is what should keep you up at night. Crosswork is a network management platform — by design, it has credentials and access to the infrastructure it manages. If any one of these unauthenticated functions provides a beachhead, attackers gain access to whatever Crosswork can reach. The CVSS 10 doesn't differentiate between a low-privilege diagnostic endpoint and a credential management interface; the blast radius of a compromise does.

Your immediate actions: treat every Crosswork interface as potentially unauthenticated until Cisco publishes enumeration of the affected functions. Segment Crosswork's network connectivity aggressively — assume lateral movement is possible through this platform. Demand from your Cisco representative the specific function enumeration that the advisory withholds. The EPSS score of 0.00453 reflects current activity, not capability — historically, authentication failures at this severity level see weaponization within 60-120 days of disclosure. Your patch timeline should reflect that window, not the current exploit probability.