Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Crosswork Security Hardening Release: August 2026 CVE-2026-20030 CVE-2026-20357 CVE-2026-20358 CVE-2026-20359 Critical 10.0 Cisco Secure Workload Software Security Hardening Release: August 2026 CVE-2026-20231 CVE-2026-20315 CVE-2026-20317 CVE-2026-20318 CVE-2026-20319 Critical 10.0 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability CVE-2026-20320 High 7.5 Cisco Unified Intelligence Center SQL Injection Vulnerability CVE-2026-20327 Medium 6.5 Cisco RoomOS Stack Overflow Vulnerability CVE-2026-20302 Medium 6.1 Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability CVE-2026-20232 Medium 5.4 Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability CVE-2026-20177 Medium 5.3 Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability CVE-2026-20314 Medium 5.0 To fully remediate the vulnerabilities that were disclosed on August 19, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery . Security Impact Rating: Informational
CSIRTS triage
- What
- Cisco PSIRT advance notification of upcoming security advisories for multiple product lines.
- Who is affected
- Organizations using Cisco BroadWorks, Industrial Ethernet switches, Contact Center, RoomOS, Secure Firewall, Secure Workload, and Unified Intelligence Center products.
- Urgency
- Medium urgency as an advance notice; detailed remediation urgency will depend on the severity of individual advisories published August 19, 2026.
- Action
- Monitor Cisco PSIRT advisories published August 19, 2026 and plan upgrades to fixed software versions.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-200300.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203570.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203580.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203590.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202310.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203150.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203170.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203180.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203190.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203200.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20030 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20357 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20358 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20359 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20231 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20315 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20317 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20318 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20319 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20320 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20327 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20302 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20232 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20177 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20314 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalCisco Crosswork Security Hardening Release: August 2026cisco-psirt
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workloadncsc-nl
- medium[NEW] [medium] Cisco Unified Contact Center Enterprise: Vulnerability allows manipulation of filescert-bund
- medium[NEW] [medium] Cisco Unified Intelligence Center: Vulnerability enables SQL injectioncert-bund
- high[NEW] [high] Cisco Secure Workload: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Cisco Industrial Ethernet 1000 Series Switches: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Cisco products (20 August 2026)cert-fr-avis
- criticalCVE-2026-20359: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cro…nvd
- criticalCVE-2026-20358: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cro…nvd
- criticalCVE-2026-20357: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Cro…nvd
- mediumCVE-2026-20327: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center cou…nvd
- highCVE-2026-20320: A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow …nvd
Recent advisories for Cisco Advance Notification
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCisco Advance Notification for Publication of September 2, 2026, Security Advisoriescisco-psirt · 2026-09-02
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco-psirt · 2026-08-05
- highCisco Advance Notification for Publication of July 15, 2026, Security Advisoriescisco-psirt · 2026-07-15
- highCisco Advance Notification for Publication of July 1, 2026, Security Advisoriescisco-psirt · 2026-07-01
More from Cisco Security Advisories
- criticalCisco IOS XR Software Security Hardening Release: September 20262026-09-03
- criticalCisco Advance Notification for Publication of September 2, 2026, Security Advisories2026-09-02
- criticalCisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability2026-09-02
- mediumCisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities2026-09-02
- highCisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of …2026-09-02