Cisco has released security updates to address vulnerabilities in Cisco IOS XR Software and Cisco BroadWorks.
The affected products include all versions of Cisco IOS XR Software, as well as versions of the Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, Cisco BroadWorks Profile Server, and Cisco BroadWorks Xtended Services Platform prior to RI.2026.07.
Seven vulnerabilities, ranging from CVE-2026-20274 to CVE-2026-20280, have been addressed in Cisco IOS XR Software.
These vulnerabilities are attributed to improper resource lifecycle management, incorrect calculations, insufficient control flow management, failure of protection mechanisms, inadequate input sanitization, improper access control, and insufficient exception checking and handling.
In Cisco BroadWorks, the CVE-2026-20320 vulnerability has been resolved; it is described as a critical information disclosure vulnerability.
The affected versions of Cisco IOS XR Software are 7.3.2, 7.9.2, 7.9.21, 7.10.2, 7.11.2, 7.11.21, 24.1.2, 24.2.2, 24.2.21, 24.3.2, 24.4.2, 25.1.2, 25.2.21, 25.4.1, 25.4.2, 26.1.2, 26.2.1, 26.2.2, And 26.3.1.
The version of Cisco BroadWorks to which the update applies is RI.2026.07.
Follow the instructions on the reference site to update to the latest version with the Vulnerability Patch.