logo

CVSS 10.0 Alert: Critical Cisco Secure Workload Exploit Grants Unauthenticated Site Admin Access

ID: bda25c05-7011-5582-8fad-0de9d585437f

STIX ID: report--bda25c05-7011-5582-8fad-0de9d585437f

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

Cisco issued an urgent advisory for CVE-2026-20223 — a maximum-severity (CVSS 10.0) access-control flaw in Cisco Secure Workload’s internal REST APIs that allows unauthenticated remote attackers to bypass tenant isolation and operate with Site Admin privileges, enabling data exfiltration, microsegmentation tampering, configuration changes, and cross-tenant persistence; Cisco provides fixed versions for supported releases and requires migration for legacy releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.