Critical Vulnerability in Cisco Secure Workload Threatens Enterprise API Security
ID: 5f14080e-25b9-56be-8a6b-3dd9d5a24a18
STIX ID: report--5f14080e-25b9-56be-8a6b-3dd9d5a24a18
Feed Name: GBHackers
Cisco disclosed a critical CVE-2026-20223 flaw in Secure Workload that allows unauthenticated attackers to gain Site Admin-level access via internal REST API endpoints (CVSS 10.0, CWE-306). SaaS instances were auto-patched; on-premises customers must upgrade to fixed releases (3.10.8.3, 4.0.3.17 or later); there are no workarounds, and organizations are advised to patch immediately, audit API access, restrict endpoint exposure, and monitor for unauthorized changes. Cisco reported no evidence of active exploitation as of May 20, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
