TL;DR
Cisco fixed a critical SQL injection flaw in Crosswork, tracked as CVE-2026-20030 at CVSS 10.0. The same hardening release patches three more critical bugs. Cisco separately fixed an XML external entity flaw in BroadWorks. No exploitation has been confirmed for any of them.
- Product: Cisco (2 products)
- Vulnerabilities: 4 flaws (CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, CVE-2026-20320)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: Crosswork Security Hardening Release: August 2026
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-20030 | 10 | CWE-89 | — | Not exploited |
| CVE-2026-20357 | 10 | CWE-306 | — | Not exploited |
| CVE-2026-20358 | 10 | CWE-73 | — | Not exploited |
| CVE-2026-20320 | 7.5 | CWE-611 | — | Not exploited |
Why It Matters
Crosswork automates and controls large service provider networks. A break in that layer therefore threatens network-wide operations. The Cisco Crosswork SQL injection flaw reaches the maximum CVSS score of 10.0.
An unauthenticated, remote attacker needs no user interaction to strike. Three companion flaws also score 10.0 or 9.9. Together, they could expose data, bypass authentication, and control files.
How the Attack Works
Cisco grouped these issues by weakness class, then assigned one CVE per group. Each score reflects the worst case in its category.
CVE-2026-20030 maps to CWE-89, a SQL command injection. Crafted input reaches a database query without proper neutralization. The Cisco Crosswork SQL injection therefore lets an attacker manipulate backend queries. Cisco found the bugs through internal testing, which included frontier AI models.
The Companion Crosswork Flaws
CVE-2026-20357 covers missing authentication for a critical function, at 10.0. CVE-2026-20358 covers external control of a file system, also at 10.0. CVE-2026-20359 involves poorly protected credentials, scoring 9.9. Full details sit in the Cisco Crosswork hardening advisory.
The BroadWorks XXE Flaw
Cisco also patched CVE-2026-20320, an out-of-band blind XXE bug in BroadWorks, rated 7.5. The OCI XML parser resolves external entities by default. As a result, a remote, unauthenticated attacker could read sensitive files. Sandesh M Gawai reported it, per the Cisco BroadWorks XXE advisory.
Affected Versions
The Crosswork flaws affect the Data Gateway, Network Controller, and Planning platforms. Releases 7.2.1 and earlier are vulnerable. The BroadWorks bug affects releases earlier than RI.2026.07. Cisco does not publish install counts, so exposure estimates remain unavailable.
Patch and Mitigation Steps
Cisco confirms no workarounds exist for either advisory. Upgrade Crosswork to release 7.2.1-SP. Move BroadWorks products to RI.2026.07 or later. Apply both updates soon, since the Crosswork bugs need no authentication.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.