

Affected Environment
Cisco Secure Workload, Crosswork, BroadWorks, Packaged and Unified Contact Center Enterprise, RoomOS, IE 1000 switches and Unified Intelligence Center.
Threat Overview
Multiple vulnerabilities allow access control bypass, XML external entity injection, SQL injection, server-side request forgery, stored XSS and buffer overflow.
Exposure Timeline
Disclosed 19 August 2026 through Cisco's internal security hardening reviews, with fixed releases available across all affected product lines.
Attack Surface
Management interfaces, OCI-P provisioning services, HTTP request handlers, USB drivers and web-based configuration pages across Cisco product lines.
Technical Root Cause
Command and SQL injection, improper access control, external control of file system, insufficiently protected credentials and memory buffer flaws.
Exploitation Pathway
Attackers send crafted XML, HTTP or USB payloads to bypass authentication, execute arbitrary code or read internal database contents.
Operational Impact
Exploitation risks unauthorized access, information disclosure, arbitrary code execution, cross-site scripting and denial-of-service across affected Cisco platforms.
Strategic Impact
Rated Critical for all government and business entity sizes given Cisco's footprint across contact centre, collaboration and network infrastructure.
Required Mitigation
Upgrade all affected Cisco software to fixed releases immediately; no workarounds are available for most of these vulnerabilities.
Incident Response Guidance
Monitor authentication logs for privilege escalation attempts, review configuration changes, and forward logs to a centralized logging platform.
References
Cisco Security Advisories (hardening, BroadWorks XXE, UCCE/PCCE SSRF, RoomOS, IE1K and CUIC advisories).
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




