Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.
Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.
- Critical CVSS 10.0 issues in Crosswork and Secure Workload releases
- BroadWorks blind XXE rated High (CVSS 7.5)
- Unified Intelligence Center SQL injection rated Medium (6.5)
- RoomOS stack overflow advisory previewed
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20357 | Missing Authentication for Critical Functions in Cisco Crosswork CVE-2026-20357 describes missing authentication for critical functions (CWE-306) in Cisco Crosswork, discovered by Cisco's own engineering team during a comprehensive internal security review and addressed in a software hardening release. Because the flaw requires no privileges and is reachable over the network with low attack complexity, an unauthenticated remote attacker could invoke critical functionality directly. The CVSS 10.0 score, with scope change and high confidentiality, integrity, and availability impacts, indicates successful attacks could compromise the Crosswork platform and spill over to other components it manages. Organizations running Cisco Crosswork — typically large enterprises and service providers using it for network automation — are affected. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS estimates only a 0.5% probability of exploitation within 30 days. Do: Review Cisco's August 19, 2026 Crosswork advisory for the affected version list and upgrade to the software hardening release it specifies, since version details are not included in this data. Until patched, restrict network access to Crosswork management interfaces and monitor Cisco PSIRT for updates. No workarounds or in-the-wild exploitation are documented at this time. | 10.0 group max | <1% |
| nichelikely hundreds to low thousands of enterprise/service-provider deployments (specialized platform; exact install base unknown) | ||
| CVE-2026-20317 | Improper Authentication Flaws in Cisco Secure Workload Score CVSS 10.0 CVE-2026-20317 covers multiple improper authentication issues (CWE-287) in Cisco Secure Workload, discovered internally by Cisco's engineering team during a comprehensive security review and addressed in a software hardening release. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H) indicates the flaws are exploitable over the network by an unauthenticated attacker with no user interaction, and the changed scope means successful exploitation can affect components beyond the vulnerable one. An attacker could gain high-impact modification of system state and denial of service across the deployment, though the vector indicates no direct confidentiality (data disclosure) impact. Users of Cisco Secure Workload are affected; the fix was published as part of Cisco's August 19, 2026 advisory batch, which reportedly patched nine Crosswork and Secure Workload flaws, five of which scored CVSS 10.0. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation within 30 days (37th percentile). Do: Review the Cisco Secure Workload security advisory (published August 19, 2026) for the exact affected and fixed release list, and upgrade to the corresponding software hardening release. Until patched, restrict network access to Secure Workload management and authentication interfaces to trusted administrative networks, since the flaw requires no authentication or user interaction. Given the CVSS 10.0 rating despite low current exploitation likelihood (EPSS 0.4%, no known PoC), prioritize patching within normal critical-vulnerability maintenance cycles. | 10.0 group max | <1% |
| nichelow thousands of enterprise deployments, with management/auth interfaces typically not internet-exposed | ||
| CVE-2026-20320 | Unauthenticated XXE File Read in Cisco BroadWorks OCI-P Service CVE-2026-20320 is an XML External Entity (XXE) flaw (CWE-611) in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks, where external entity resolution is allowed by default and XML entries are improperly parsed. An unauthenticated remote attacker triggers it by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service on an affected system. A successful exploit lets the attacker view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user; confidentiality is impacted, with no integrity or availability effect (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). Only BroadWorks deployments whose OCI-P interface is reachable by the attacker are exposed, and the scope of affected releases is defined by Cisco's advisory. There is currently no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation within 30 days, indicating low near-term exploitation risk. Do: Upgrade affected BroadWorks systems to the fixed releases listed in the Cisco security advisory published August 19, 2026. Until patching, restrict network access to the OCI-P interface with firewall or ACL rules so only trusted provisioning systems can reach it, and audit whether OCI-P is exposed to the internet or shared networks. Monitor Cisco PSIRT for updates, as no public PoC exists yet but pre-authentication makes internet-exposed deployments the priority. | 7.5 | <1% |
| massLikely thousands to tens of thousands of BroadWorks server deployments serving millions of subscribers via hundreds of service providers; the directly… | ||
| CVE-2026-20327 | Authenticated Blind SQL Injection in Cisco Unified Intelligence Center Web Interface Cisco Unified Intelligence Center contains a blind SQL injection flaw (CWE-89) in its web-based management interface, caused by insufficient validation of user-supplied input. To trigger it, an attacker who already holds valid user credentials on the affected device sends a crafted request to the management interface. A successful exploit lets the attacker read the contents of the device's internal database, with no impact on integrity or availability. Any organization running Cisco Unified Intelligence Center is exposed, though the requirement for valid, low-privileged credentials raises the bar for exploitation. As of publication there is no known exploitation, no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS puts the 30-day exploitation probability at roughly 0.2%. Do: Check whether Cisco Unified Intelligence Center is deployed in your environment and apply the fix released with Cisco's August 19, 2026 advisories, consulting the official advisory for the affected and fixed release lists. Until patched, restrict access to the web-based management interface to trusted management networks and limit which accounts hold valid credentials on the device. Monitor authentication logs for low-privileged accounts querying the management interface, since exploitation requires valid credentials. | 6.5 | <1% |
| largetens of thousands of enterprise deployments |
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Crosswork Security Hardening Release: August 2026 CVE-2026-20030 CVE-2026-20357 CVE-2026-20358 CVE-2026-20359 Critical 10.0 Cisco Secure Workload Software Security Hardening Release: August 2026 CVE-2026-20231 CVE-2026-20315 CVE-2026-20317 CVE-2026-20318 CVE-2026-20319 Critical 10.0 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability CVE-2026-20320 High 7.5 Cisco Unified Intelligence Center SQL Injection Vulnerability CVE-2026-20327 Medium 6.5 Cisco RoomOS Stack Overflow…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.