Cisco Patched Critical XXE Flaw in BroadWorks Platform
Cisco has issued security updates to address a high-severity vulnerability in its BroadWorks platform. The flaw, tracked as CVE-2026-20320, is an out-of-band blind XML External Entity (XXE) injection issue in the Open Client Interface (OCI) XML parser. This means that unauthenticated remote attackers can disclose sensitive configuration information from affected systems.
The vulnerability affects BroadWorks environments where the vulnerable OCI parsing behavior is present and carries a CVSS score of 7.5 out of 10. According to Cisco, this issue requires neither authentication nor user interaction and is considered network-exploitable.
Cisco has confirmed that multiple BroadWorks components are affected when running vulnerable releases, independent of device configuration. The affected products include the BroadWorks Application Delivery Platform, Application Server, Profile Server, and Xtended Services Platform.
The company has fixed CVE-2026-20320 in BroadWorks release RI.2026.07 and urges administrators to identify every BroadWorks deployment, determine whether OCI-P is enabled or reachable, and verify the installed release against Cisco's advisory.