logo

Max severity Cisco Secure Workload flaw gives Site Admin privileges

ID: 858a1487-34d1-547a-b955-7023f74273cb

STIX ID: report--858a1487-34d1-547a-b955-7023f74273cb

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Sergiu Gatlan

...
...

Cisco issued a security advisory for CVE-2026-20223, a maximum-severity vulnerability in Secure Workload's internal REST APIs that could let unauthenticated attackers assume Site Admin privileges and perform cross-tenant reads/changes; on-premises fixes are available (e.g., 3.10.8.3, 4.0.3.17) and the cloud SaaS has been remediated, with Cisco reporting no observed exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.