logo

Cisco Secure Workload Flaw Enables Unauthorized API Access

ID: 1f299935-cf4e-5cc8-b743-82dcc8a8e648

STIX ID: report--1f299935-cf4e-5cc8-b743-82dcc8a8e648

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Lucas Martin

...
...

Cisco disclosed CVE-2026-20223, a critical (CVSS 10.0) authentication-bypass in Cisco Secure Workload that allows unauthenticated attackers to gain Site Admin privileges via internal REST APIs, enabling cross-tenant access and full administrative control. Affected on-premises releases require immediate patching (upgrade to 3.10.8.3 or 4.0.3.17); SaaS deployments have been fixed by Cisco. No workarounds exist and Cisco reports no known active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.