Cisco released security updates for multiple products after disclosing at least 15 vulnerabilities, including eight critical issues and several high-severity flaws. The most serious bugs affect Cisco Secure Workload and Cisco Crosswork Data Gateway, where vulnerabilities rated up to CVSS 10.0 could allow authentication bypass, remote code execution, path traversal, file overwrite or deletion, data manipulation, and filesystem compromise. Cisco issued fixes including Secure Workload 4.0.4.16 and 3.10.9.1 and patches for Crosswork 7.2.1-SP, while urging customers to follow product-specific security bulletins and upgrade affected systems promptly.
Cisco also patched a high-severity XML External Entity flaw in Cisco BroadWorks, tracked as CVE-2026-20320, which could let unauthenticated attackers read sensitive configuration data and files through the OCI-P provisioning service; affected BroadWorks releases earlier than RI.2026.07 should be upgraded because no workaround is available. Additional fixes were issued for products including Network Controller, Planning, Packaged Contact Center Enterprise, RoomOS, Industrial Ethernet 1000 Series Switches, Unified Intelligence Center, and Cisco Talos Intelligence for Enterprise Security Cloud. Cisco said it had no evidence of active exploitation at the time of disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Cisco fixed CVE-2026-20320, a high-severity XXE vulnerability in BroadWorks, in release RI.2026.07 for the affected BroadWorks product families. The flaw could allow unauthenticated remote attackers to read sensitive configuration data and files via crafted XML sent to OCI-P services.
Cisco released Secure Workload versions 4.0.4.16 and 3.10.9.1 to address five vulnerabilities, four of them critical. The issues included authentication bypass, improper access control, command injection, path traversal, and memory corruption weaknesses.
Cisco released Crosswork version 7.2.1-SP to fix four critical vulnerabilities, including CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359. The flaws could enable remote code execution, authentication bypass, path traversal, and file overwrite or deletion.
On August 20, 2026, Cisco announced patches for 15 vulnerabilities affecting products including Crosswork, Secure Workload, and BroadWorks. Cisco said the most severe issues were in Crosswork and Secure Workload and stated it was not aware of in-the-wild exploitation.
Cisco published advisory cisco-sa-bworks-xxe-uwUd7CEt on August 19, 2026, for CVE-2026-20320, a high-severity XXE vulnerability in the BroadWorks Open Client Interface XML Parser. Cisco said releases earlier than RI.2026.07 were affected and that no workaround was available.
On August 19, 2026, Splunk published an advisory covering 17 vulnerabilities across Splunk MCP Server, Splunk AI Toolkit, Splunk Connect for Kafka, Cisco Talos Intelligence for Enterprise Security Cloud, and Splunk On-Call. The advisory included a critical RCE flaw, CVE-2026-76404, in Splunk MCP Server and recommended upgrading affected components.
Cisco Talos Intelligence for Enterprise Security Cloud addressed multiple vulnerabilities in version 1.0.3, including CVE-2026-76389, CVE-2026-76390, and a critical issue identified by one source as CVE-2026-76404. The patched issues included SSRF, OpenAPI specification exposure, and a potential remote code execution flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcecyberaccord.com
Open sourceacn.gov.it
Open sourceheise.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.