CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Cisco security advisory (AV26-834)

unknown
Serial Number: AV26-834 Date: August 20, 2026 As of August 19, 2026, Cisco is affected by vulnerabilities in the following products: BroadWorks Application Delivery Platform Prior to RI.2026.07 BroadWorks Application Server Prior to RI.2026.07 BroadWorks Profile Server Prior to RI.2026.07 BroadWorks Xtended Services Platform Prior to RI.2026.07 Cisco Crosswork Planning Prior to 7.2.1-SP Cisco Crosswork Data Gateway Prior to 7.2.1-SP Cisco Crosswork Network Controller Prior to 7.2.1-SP Cisco Secure Workload Version 3.10 prior to 3.10.9.1 Version 4.0 prior to 4.0.4.16 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Secure Workload Software Security Hardening Release: August 2026 Cisco Crosswork Security Hardening Release: August 2026 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability Cisco Security Advisories

CSIRTS triage

vendor: CiscoOtheraffected: BroadWorks Application Delivery Platform prior to RI.2026.07, BroadWorks Application Server prior to RI.2026.07, BroadWorks Profile Server prior to RI.2026.07, BroadWorks Xtended Services Platform pri
What
Cisco products contain unspecified vulnerabilities including blind XML external entity injection affecting multiple product lines.
Who is affected
Organizations running Cisco BroadWorks, Crosswork, and Secure Workload platforms below specified versions are affected.
Urgency
Urgency unknown; Cisco has released security hardening updates and patches should be applied as available.
Action
Apply Cisco Crosswork and BroadWorks out-of-band patches and update Secure Workload to fixed versions (3.10.9.1 or 4.0.4.16).

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-834

More from Canadian Centre for Cyber Security