Cisco BroadWorks Vulnerability Exposes Sensitive Data to Attackers

Cisco BroadWorks Vulnerability Exposes Sensitive Data to Attackers

First seen 20 Aug 2026, 18:28 UTC CybersecuritynewsGround.Newswww.securityweek.com 95% similarity 72.0

Article Content

Browse articles
ThreatCluster

Cisco has issued security updates for a critical XML External Entity injection vulnerability in Cisco BroadWorks, tracked as CVE-2026-20320. This flaw allows unauthenticated remote attackers to access sensitive configuration data and files from affected systems. The vulnerability, identified in the Open Client Interface XML Parser, has a CVSS score of 7.5 and impacts multiple BroadWorks components. Potential consequences include remote code execution, authentication bypasses, and path traversal attacks. Cisco has urged users to apply the updates immediately to mitigate risks. The vulnerability was published on August 19, 2026, and is considered high-severity due to its potential impact on data security.

Key Points: • CVE-2026-20320 allows unauthenticated remote access to sensitive data. • The vulnerability affects multiple components of Cisco BroadWorks. • Cisco has released urgent security updates to address the issue.

ThreatCluster AI How this analysis works

Timeline

2026-08-19
CVE-2026-20320 published
Cisco disclosed a high-severity XML External Entity injection vulnerability affecting BroadWorks.
Ground.News
2026-08-20
Security updates released
Cisco released critical updates for BroadWorks to mitigate the XML External Entity injection vulnerability.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story