Cisco disclosed a broad set of security flaws across enterprise products, including critical unauthenticated remote code execution, arbitrary command execution, and authentication bypass vulnerabilities affecting Smart Software Manager On-Prem, Integrated Management Controller, Nexus Dashboard Fabric Controller, and Secure Firewall Management Center. Additional high- and medium-severity issues impact IOS XE and other Cisco platforms, enabling denial of service, privilege escalation, arbitrary file write, server-side request forgery, secure boot bypass, sensitive information exposure, and cross-site scripting. Many of the vulnerabilities affect web-based management interfaces and network-facing services, raising the risk to remotely reachable administrative systems.
One of the most severe issues, CVE-2026-20223, affects Cisco Secure Workload and allows an unauthenticated attacker to bypass REST API authentication and perform administrative actions. The flaw, tracked as CWE-306 and rated CVSS 10.0, can expose configuration data, alter microsegmentation policies, and enable cross-tenant access with Site Admin-level impact in both SaaS and on-premises deployments. Cisco said no workaround is available and released fixes in versions 3.10.8.3 and 4.0.3.17; reporting cited no known active exploitation or public proof-of-concept at the time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco addressed CVE-2026-20223, a critical authentication bypass in Cisco Secure Workload, in versions 3.10.8.3 and 4.0.3.17. The flaw allowed unauthenticated access to internal REST API endpoints and administrative actions in both SaaS and on-premises deployments.
Cisco disclosed or updated a roundup of security advisories affecting products including IOS XE, Nexus Dashboard, Integrated Management Controller, Smart Software Manager On-Prem, and Secure Firewall. The issues included critical remote code execution, authentication bypass, arbitrary command execution, denial of service, privilege escalation, and other flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.