Cisco has announced new security updates addressing 15 vulnerabilities across its product portfolio. Among the most urgent fixes are issues in Crosswork and Secure Workload, where several flaws carry critical or near-critical severity scores. Cisco says it is not aware of active exploitation “in the wild,” but the potential impact of successful attacks is substantial.
This article summarizes what Cisco patched, which products were affected, and the security risks that the releases are meant to reduce—so administrators can prioritize patching and verify their environments.
Crosswork 7.2.1-SP addresses multiple critical CVEs
For Crosswork, Cisco released version 7.2.1-SP with fixes for four critical-severity CVEs. Three of these issues received a 10/10 CVSS score, reflecting maximum impact potential, while the fourth is rated 9.9/10—just short of the maximum.
According to Cisco, each CVE groups multiple underlying issues within a shared vulnerability class. The vulnerabilities described include:
- CVE-2026-20030: SQL injection and related problems.
- CVE-2026-20357: missing authentication.
- CVE-2026-20358: external control of the file system.
- CVE-2026-20359: insufficient protection of credentials.
If an attacker could exploit these weaknesses, the outcomes Cisco highlights include remote code execution (RCE), authentication bypass, path traversal, and file overwrite or deletion. In practice, that combination points to both compromise of system behavior and potential manipulation of files—capabilities that can significantly raise breach severity.
Secure Workload updates fix five CVEs
Cisco also pushed updates for Secure Workload, releasing two fixed versions: 4.0.4.16 and 3.10.9.1. These releases address five CVEs, including four that Cisco rates as critical.
As with Crosswork, Cisco explains that each CVE bundles multiple issues under a common vulnerability theme. The CVEs called out include:
- CVE-2026-20315 and CVE-2026-20317: improper access control and authentication defects that may lead to bypasses.
- CVE-2026-20231: code/OS command injection issues.
- CVE-2026-20318: input validation problems and path traversal.
- CVE-2026-20319: buffer overflows and out-of-bounds write conditions.
These categories matter because they map to realistic exploitation paths. Authentication and access-control failures can reduce the effort needed to gain unauthorized entry, while injection and memory corruption bugs can raise the likelihood of full system compromise.
BroadWorks Open Client Interface XML parser flaw
Beyond Crosswork and Secure Workload, Cisco also resolved a high-severity security weakness in the Open Client Interface (OCI) XML parser used by BroadWorks components. Cisco describes this flaw as remotely exploitable without authentication, with the ability to read sensitive configuration information.
The issue is tracked as CVE-2026-20320. Cisco attributes the root cause to external entity resolution being allowed by default, enabling attackers to submit crafted XML messages. With that mechanism, an attacker could access sensitive files while operating under BroadWorks user privileges.
Cisco states that the vulnerability is addressed in version RI.2026.07 of the BroadWorks Application Delivery Platform, BroadWorks Application Server, BroadWorks Profile Server, and BroadWorks Xtended Services Platform.
Additional fixes across other Cisco products
In addition to the headline updates, Cisco rolled out fixes for medium-severity weaknesses in multiple offerings. The announcement includes Unified Intelligence Center, RoomOS, Industrial Ethernet (IE) 1000 series switches, and Packaged Contact Center Enterprise (CCE) and Unified Contact Center Enterprise (CCE).
While these are described as medium severity in the advisory context, administrators should still evaluate exposure based on use case, network reachability, and how those systems integrate with other parts of an organization.
What Cisco says about exploitation status
Cisco indicates that it is not aware of any of the reported vulnerabilities being exploited “in the wild.” Even so, the combination of critical CVEs, remote exploitation potential, and impacts like RCE and credential-related weaknesses means organizations should plan patching promptly rather than waiting for proof of active attacks.
For affected deployments, Cisco notes that more details are available through its security advisories page. That source typically provides the most up-to-date guidance on affected versions and recommended remediation steps.
Practical next steps for administrators
If you manage environments that include the impacted Cisco platforms, focus on verification and prioritization. A good approach is:
- Identify installed versions of Crosswork and Secure Workload, then compare them with Cisco’s fixed releases.
- Validate BroadWorks component versions against the RI.2026.07 update for CVE-2026-20320.
- Assess exposure: consider whether management interfaces, APIs, or XML endpoints are reachable from untrusted networks.
- Prioritize critical and near-critical issues first, especially those tied to authentication bypass, injection, and file system manipulation.
- Follow up with monitoring after patching, watching for unusual login behavior, command execution indicators, or unexpected file activity.
By addressing the most severe flaws first and confirming that systems are actually updated to the versions Cisco lists, you reduce the chance that attackers can leverage known weaknesses.
Conclusion
Cisco patches multiple high-impact vulnerabilities, with particular urgency around Crosswork and Secure Workload. The released updates fix critical flaws that may enable remote code execution, authentication bypass, path traversal, and file overwrite or deletion. Cisco also corrected a remotely exploitable XML parser issue in BroadWorks, plus additional medium-severity weaknesses in several other products.
Even though Cisco reports no known in-the-wild exploitation, organizations using these platforms should treat the updates as a priority and move quickly to the corresponding fixed versions.
Source: https://www.securityweek.com/cisco-patches-critical-crosswork-secure-workload-vulnerabilities/
