VORANT. Threat Intelligence Sign in Get the full feed

Cisco Patches BroadWorks, Crosswork, Secure Workload Flaws

routine vulnerability telecommunications

CERT-FR advisory lists multiple Cisco vulnerabilities in BroadWorks, Crosswork, and Secure Workload enabling RCE, privilege escalation, and data exposure.

CERT-FR published an advisory detailing multiple vulnerabilities discovered across several Cisco product lines, including the BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform, as well as Crosswork and Secure Workload. The flaws range in impact from remote code execution and privilege escalation to SQL injection, data integrity and confidentiality breaches, and security policy bypass. Cisco has released three security advisories (bworks-xxe, hardening-crosswork, hardening-csw1) covering ten CVEs disclosed on 19 August 2026.

No evidence of active exploitation is mentioned in the advisory; this is a vendor patch notice requiring administrators to update affected systems to the fixed versions (BroadWorks RI.2026.07, Crosswork 7.2.1-SP, Secure Workload 4.0.4.16 or 3.10.9.1) as detailed in Cisco's bulletins.

Mentioned in this report

Vulnerabilities CVE-2026-20030CVE-2026-20231CVE-2026-20315CVE-2026-20317CVE-2026-20318CVE-2026-20319CVE-2026-20320CVE-2026-20357CVE-2026-20358CVE-2026-20359

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1058

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free