logo

Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating

ID: 8d4506fb-8e45-5fda-8bfd-151330c4b117

STIX ID: report--8d4506fb-8e45-5fda-8bfd-151330c4b117

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2026-05-22

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

Cisco disclosed a critical CVE-2026-20223 vulnerability in Secure Workload (CVSS 10.0) where insufficient validation and missing authentication on internal REST API endpoints could let unauthenticated attackers read sensitive data and perform Site Admin-level configuration changes across tenant boundaries; Cisco provided fixed releases (3.10.8.3, 4.0.3.17), stated SaaS was already remediated, warned no workarounds exist, and reported no evidence of active exploitation at the time of disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.