Cisco announced the release of patches for 15 vulnerabilities across its product lineup, addressing critical and high-severity flaws in Crosswork and Secure Workload. The company stated that it is not aware of any active exploitation of these defects in the wild.
Crosswork version 7.2.1-SP includes fixes for four critical-severity vulnerabilities. Three of these, identified as CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, carry a maximum CVSS score of 10.0. The fourth, CVE-2026-20359, has a score of 9.9.
Cisco noted that these identifiers group multiple issues under common vulnerability classes, including SQL injection, missing authentication, external control of file systems, and insufficient credential protection. Successful exploitation could enable remote code execution, authentication bypass, path traversal, and file manipulation attacks.
Secure Workload versions 4.0.4.16 and 3.10.9.1 address five additional vulnerabilities, four of which are rated critical. These include improper access control and authentication bugs (CVE-2026-20315 and CVE-2026-20317), code and OS command injections (CVE-2026-20231), and input validation and path traversal issues (CVE-2026-20318). A fifth vulnerability, CVE-2026-20319, covers buffer overflows and out-of-bounds write issues.
A high-severity flaw in the BroadWorks Open Client Interface XML parser, tracked as CVE-2026-20320, was also resolved. This defect allowed remote attackers to read sensitive configuration information without authentication by sending crafted XML messages, due to external entity resolution being enabled by default.
Fixes for this issue are included in version RI.2026.07 of the BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform.