logo

Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access

ID: 7c2ab893-798d-5add-917e-e19ba5ed2fa4

STIX ID: report--7c2ab893-798d-5add-917e-e19ba5ed2fa4

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Abinaya

...
...

Cisco disclosed a critical CVE-2026-20223 in Secure Workload where improper authentication/validation of internal REST APIs can be exploited by unauthenticated attackers to gain Site Admin privileges (CVSS 10.0). The flaw affects both SaaS and on-prem deployments, carries cross-tenant risks, has no workaround, and fixed software versions are provided (e.g., 3.10.8.3, 4.0.3.17); Cisco reports no active exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.