Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access
ID: 7c2ab893-798d-5add-917e-e19ba5ed2fa4
STIX ID: report--7c2ab893-798d-5add-917e-e19ba5ed2fa4
Feed Name: cybersecurityNews.com
Threat Score
Cisco disclosed a critical CVE-2026-20223 in Secure Workload where improper authentication/validation of internal REST APIs can be exploited by unauthenticated attackers to gain Site Admin privileges (CVSS 10.0). The flaw affects both SaaS and on-prem deployments, carries cross-tenant risks, has no workaround, and fixed software versions are provided (e.g., 3.10.8.3, 4.0.3.17); Cisco reports no active exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
