In plain language
What this advisory means
On August 19, 2026, Cisco announced several security advisories addressing multiple vulnerabilities in various products. These issues range from critical to medium severity and could allow attackers to compromise systems in different ways, such as executing harmful code, injecting malicious data, or causing denial of service. Cisco recommends customers update to the latest fixed software versions to fully resolve these vulnerabilities.
Technical explanation
How the issue affects the environment
Cisco released security advisories covering multiple vulnerabilities such as critical-rated issues in Crosswork and Secure Workload software with a CVSS base score of 10.0, including XML External Entity (XXE) injection in BroadWorks, SQL injection in Unified Intelligence Center, stack overflow in RoomOS, stored cross-site scripting (XSS) and denial of service (DoS) in Industrial Ethernet switches, and server-side request forgery (SSRF) in Contact Center products. These vulnerabilities can lead to remote code execution, unauthorized data access, or service disruption. Cisco advises upgrading to the fixed software releases detailed in the advisories for mitigation.
Operational impact
Why teams should care
Organizations using Cisco products affected by these vulnerabilities risk operational disruptions, data breaches, service outages, and potential unauthorized access. Exploits could lead to costly downtime and loss of customer trust. It is important for businesses to apply Cisco's recommended software updates promptly to reduce exposure and maintain network security.
Immediate action
Cisco strongly recommends upgrading to the fixed software versions referenced in the published advisories to fully remediate the disclosed vulnerabilities.
Affected and fixed releases
Temporary risk reduction
Cisco specifies that no workarounds are available for these vulnerabilities at this time.
Evidence and validation checklist
- Official Cisco PSIRT advisory published August 19, 2026
- List of specific CVEs with severity ratings and CVSS scores
- Cisco product names and affected components
- Recommendation to upgrade to fixed software
- Statement that no workarounds are available
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
