Cisco security advisory (AV26-834)
Serial Number: AV26-834 Date: August 20, 2026 As of August 19, 2026, Cisco is affected by vulnerabilities in the following products: BroadWorks Application Delivery Platform Prior to RI.2026.07 BroadWorks Application Server Prior to RI.2026.07 BroadWorks Profile Server Prior to RI.2026.07 BroadWorks Xtended Services Platform Prior to RI.2026.07 Cisco Crosswork Planning Prior to 7.2.1-SP Cisco Crosswork Data Gateway Prior to 7.2.1-SP Cisco Crosswork Network Controller Prior to 7.2.1-SP Cisco Secure Workload Version 3.10 prior to 3.10.9.1 Version 4.0 prior to 4.0.4.16 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Secure Workload Software Security Hardening Release: August 2026 Cisco Crosswork Security Hardening Release: August 2026 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability Cisco Security Advisories
CSIRTS triage
- What
- Cisco products contain unspecified vulnerabilities including blind XML external entity injection affecting multiple product lines.
- Who is affected
- Organizations running Cisco BroadWorks, Crosswork, and Secure Workload platforms below specified versions are affected.
- Urgency
- Urgency unknown; Cisco has released security hardening updates and patches should be applied as available.
- Action
- Apply Cisco Crosswork and BroadWorks out-of-band patches and update Secure Workload to fixed versions (3.10.9.1 or 4.0.4.16).
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-834
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24