logo

Critical Vulnerability in Cisco Secure Workload Threatens Enterprise API Security

ID: 5f14080e-25b9-56be-8a6b-3dd9d5a24a18

STIX ID: report--5f14080e-25b9-56be-8a6b-3dd9d5a24a18

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Divya

...
...

Cisco disclosed a critical CVE-2026-20223 flaw in Secure Workload that allows unauthenticated attackers to gain Site Admin-level access via internal REST API endpoints (CVSS 10.0, CWE-306). SaaS instances were auto-patched; on-premises customers must upgrade to fixed releases (3.10.8.3, 4.0.3.17 or later); there are no workarounds, and organizations are advised to patch immediately, audit API access, restrict endpoint exposure, and monitor for unauthorized changes. Cisco reported no evidence of active exploitation as of May 20, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.