logo

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

ID: 9e133ac3-cd08-5d08-ad72-9529e3116b50

STIX ID: report--9e133ac3-cd08-5d08-ad72-9529e3116b50

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: [email protected] (The Hacker News)

...
...

**CVE-2026-20223 (CVSS 10.0): Critical unauthenticated REST API vulnerability in Cisco Secure Workload** — Cisco released fixes for Secure Workload (fixed in 3.10.8.3 and 4.0.3.17) after discovering an API authentication/validation flaw that could let remote, unauthenticated actors read sensitive data and make cross-tenant configuration changes as a Site Admin; no workaround exists and Cisco reports no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.