Cisco Secure Workload Flaw Enables Unauthorized API Access
ID: 1f299935-cf4e-5cc8-b743-82dcc8a8e648
STIX ID: report--1f299935-cf4e-5cc8-b743-82dcc8a8e648
Feed Name: Cyber Press
Threat Score
Cisco disclosed CVE-2026-20223, a critical (CVSS 10.0) authentication-bypass in Cisco Secure Workload that allows unauthenticated attackers to gain Site Admin privileges via internal REST APIs, enabling cross-tenant access and full administrative control. Affected on-premises releases require immediate patching (upgrade to 3.10.8.3 or 4.0.3.17); SaaS deployments have been fixed by Cisco. No workarounds exist and Cisco reports no known active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
