Back Ground.News Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data
Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems. Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified …
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.
Important security updates have been released for Cisco BroadWorks, Crosswork Security and Secure Workload.
To view factuality data please Upgrade to Premium
To view ownership data please Upgrade to Vantage
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
