Skip to content
Cisco BroadWorks Vulnerability Exposes Sensitive Data to Remote Attackers

Cisco BroadWorks Vulnerability Exposes Sensitive Data to Remote Attackers

First seen 20 Aug 2026, 18:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 21, 2026 at 18:17 UTC
  • •CVE-2026-20320 allows unauthenticated remote access to sensitive files in Cisco BroadWorks.
  • •The vulnerability has a CVSS score of 7.5, indicating high severity.
  • •Cisco has released security updates to address the vulnerability across affected systems.

Cisco has issued security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks, tracked as CVE-2026-20320. This flaw allows unauthenticated remote attackers to read sensitive configuration data and files from affected systems. The vulnerability, identified in the Open Client Interface XML Parser, has a CVSS score of 7.5 and could lead to various attacks, including remote code execution and authentication bypasses. Cisco has confirmed that several components of the BroadWorks platform are affected. Security updates have been released to mitigate the risks associated with this vulnerability. Organizations using Cisco BroadWorks are advised to apply these updates promptly to protect against potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-19
CVE-2026-20320 published
Cisco disclosed a high-severity XML External Entity injection vulnerability in BroadWorks.
Ground.News
2026-08-20
Security updates released
Cisco issued updates to mitigate the risks associated with CVE-2026-20320 for BroadWorks and related components.
Gbhackers
2026-08-20
Vulnerability details confirmed
Cisco confirmed that the vulnerability allows remote attackers to access sensitive configuration files on affected systems.
Cybersecuritynews

More articles in this cluster (4)

Following this threat?

Track CVE-2026-20320 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed