Cisco disclosed CVE-2026-20223, a critical CVSS 10.0 vulnerability in Cisco Secure Workload Cluster Software that allows an unauthenticated remote attacker to gain Site Admin privileges by sending crafted requests to internal REST API endpoints. The flaw stems from insufficient authentication and access validation (CWE-306) and affects both SaaS and on-premises deployments, enabling access to site resources, exposure of sensitive information, and configuration changes that can cross tenant boundaries.
Cisco said its hosted SaaS environments have already been remediated, while customers running affected versions must upgrade because no workaround is available. Fixed releases include 3.10.8.3 and 4.0.3.17, with the issue affecting version 3.9 and earlier, versions before 3.10.8.3, and versions before 4.0.3.17. Cisco and the Canadian Centre for Cyber Security urged administrators to review the advisory and apply updates promptly; Cisco said it is not aware of active exploitation and reported that the vulnerability was identified during internal security testing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-491 highlighting Cisco's May 20 security advisories and specifically calling attention to the critical Cisco Secure Workload issue. It urged administrators to review Cisco's guidance and apply the necessary updates.
Cisco made fixes available for affected on-premises deployments in versions 3.10.8.3 and 4.0.3.17, with no workaround provided. Cisco also stated that its hosted SaaS environments had already been remediated and that it was not aware of active exploitation.
Cisco disclosed CVE-2026-20223, a critical unauthorized API access vulnerability in Cisco Secure Workload caused by insufficient validation and authentication on internal REST API endpoints. The flaw can let an unauthenticated remote attacker gain Site Admin privileges, access sensitive information, and make configuration changes across tenant boundaries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcescworld.com
Open sourcesocradar.io
Open sourcethecyberexpress.com
Open sourcetheregister.com
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.