Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems. Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in […]

This article has been indexed from Cyber Security News

Read the original article: