Cisco released patches for 15 vulnerabilities across Crosswork, Secure Workload, BroadWorks, and other products, including several critical flaws that could enable remote code execution, authentication bypass, and sensitive file access. Cisco said it is not aware of any of the issues being exploited in the wild, and fixes are now available for the affected versions. #Cisco #Crosswork #SecureWorkload #BroadWorks #CVE-2026-20030 #CVE-2026-20357 #CVE-2026-20358 #CVE-2026-20359 #CVE-2026-20320
Keypoints
- Cisco patched four critical CVEs in Crosswork 7.2.1-SP.
- The Crosswork flaws could lead to RCE, authentication bypass, and file manipulation.
- Secure Workload updates fix five CVEs, including injection, access control, and buffer overflow issues.
- BroadWorks had a high-severity XML parser flaw that could expose sensitive configuration data.
- Cisco says there is no evidence of active exploitation in the wild.
Read More: https://www.securityweek.com/cisco-patches-critical-crosswork-secure-workload-vulnerabilities/