CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access
ID: bda25c05-7011-5582-8fad-0de9d585437f
STIX ID: report--bda25c05-7011-5582-8fad-0de9d585437f
Feed Name: securityonline.info
Threat Score
Cisco issued an urgent advisory for CVE-2026-20223 — a maximum-severity (CVSS 10.0) access-control flaw in Cisco Secure Workload’s internal REST APIs that allows unauthenticated remote attackers to bypass tenant isolation and operate with Site Admin privileges, enabling data exfiltration, microsegmentation tampering, configuration changes, and cross-tenant persistence; Cisco provides fixed versions for supported releases and requires migration for legacy releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
