Cisco Broadworks
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Cisco Broadworks, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Cisco Broadworks CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 1 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High6
- Medium14
Latest CVEs
The 15 most recently published vulnerabilities affecting Cisco Broadworks.
- CVE-2026-76438Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability6.5
- CVE-2026-20320A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. ...7.5
- CVE-2025-20307Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability4.8
- CVE-2025-20211Cisco BroadWorks Application Delivery Platform Software Cross-Site Scripting Vulnerability6.1
- CVE-2025-20165Cisco BroadWorks SIP Denial of Service Vulnerability7.5
- CVE-2022-20948Cisco BroadWorks Hosted Thin Receptionist Cross-Site Scripting Vulnerability5.4
- CVE-2023-20125Cisco BroadWorks Network Server TCP Denial of Service Vulnerability8.6
- CVE-2024-20270A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker ...4.8
- CVE-2023-20238A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote at...10.0
- CVE-2023-20216A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. ...4.4
- CVE-2023-20204A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack...5.4
- CVE-2023-20210A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input vali...6.0
- CVE-2023-20019A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could al...6.1
- CVE-2023-20020A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote ...8.6
- CVE-2022-20958A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attac...8.3
Product grouping is registry-driven, with AI assist and human review. How it works