CISCO has addressed a critical SQL injection vulnerability (CVE-2026-20030) in its Crosswork platform, rated 10.0 on the CVSS scale, alongside three other critical vulnerabilities, maintaining an overall status of no confirmed exploitation. The vulnerabilities threaten network operations by allowing unauthorized access and manipulation of database queries without user interaction. Cisco recommends upgrading to specific releases for mitigation.
The vulnerabilities identified include flaws in BroadWorks (CVE-2026-20320), also rated 7.5. Exposure estimates remain unpublished as install counts are not released by Cisco.