Cisco fixed a BroadWorks vulnerability that could let an unauthenticated attacker read sensitive files from exposed systems. The issue, CVE-2026-20320, is an XML external entity flaw in the Open Client Interface parser and affects BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform before RI.2026.07. Cisco says there is no evidence of active exploitation.
Why it matters: BroadWorks is widely used in communications environments, so exposed systems could leak configuration data that helps attackers move deeper into a network. Affected organizations should update to RI.2026.07 and check whether these services are internet-accessible.
Ionut Arghire
2026.08.20
100% relevant
This article is the first concrete report here of CVE-2026-20320, including affected BroadWorks components, attack conditions, and the fixed release.
← Back to all stories