Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Cisco Serves up yet Another Perfect 10 Bug with Secure Workload Admin Flaw

Cisco said no workarounds exist for the maximum-severity flaw, which affects on-premises and cloud deployments and lets unauthenticated attackers gain Site Admin access.

  • Cisco released updates patching CVE-2026-20223, a maximum-severity vulnerability allowing unauthenticated attackers to gain Site Admin privileges in Cisco Secure Workload. The flaw affects both SaaS and on-premises environments, earning a perfect 10.0 CVSS score.
  • Weak validation and authentication in internal REST API endpoints cause the flaw, Cisco explained. An attacker can "read sensitive information and make configuration changes across tenant boundaries" by sending a crafted API request.
  • Customers running Cisco Secure Workload Release 3.9 or earlier must migrate to supported versions; 3.10 users update to 3.10.8.3 and 4.0 users to 4.0.3.17. Cloud-hosted SaaS deployments are already patched and require no action.
  • Although the bug carries a 10.0 severity score, Cisco's Product Security Incident Response Team has not found evidence of active exploitation in the wild. The flaw was discovered during internal security testing, with no workarounds currently available.
  • This disclosure continues a trend of high-scoring security advisories, occurring less than a week after Cisco warned of another maximum-severity authentication bypass vulnerability in its Catalyst SD-WAN platform. Cisco has disclosed numerous 9.8-plus infrastructure flaws over the past year.
Insights by Ground AI
Podcasts & Opinions

17 Articles

Cisco has closed a vulnerability with the highest possible risk level in its Secure Workload security platform, which allows attackers to gain administrator rights and read sensitive data from corporate networks without logging in. Both local installations and cloud environments are affected.

Read Full Article

Cisco provides an update that closes a vulnerability with the highest possible risk assessment in Secure Workload.

·Germany
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cyber Security News broke the news on Thursday, May 21, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal