Cisco patches critical Cisco Secure Workload API flaw CVE-2026-20223 enabling Site Admin access

Cisco released fixes for CVE-2026-20223, a critical 10.0 vulnerability in Cisco Secure Workload Cluster Software caused by insufficient validation and authentication in internal REST API endpoints. The flaw affects SaaS and on-prem deployments and can let remote attackers read sensitive information and modify configurations across tenant boundaries with Site Admin privileges. Patched versions are 3.10.8.3 and 4.0.3.17.
Why it matters: Organizations using Cisco Secure Workload face high-impact administrative compromise and cross-tenant exposure if unpatched. Defenders should prioritize updates because exploitation requires only a crafted API request and no in-the-wild activity is needed for urgency at this severity.

Sources

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.
2026.08.21 62% relevant
This is another Cisco Secure Workload Software security event affecting the same product line, adding a new cluster of five flaws (CVE-2026-20315, CVE-2026-20317, CVE-2026-20231, CVE-2026-20318, CVE-2026-20319), updated fixed versions, and the note that SaaS customers must still update agents and connectors.
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Ionut Arghire 2026.08.20 86% relevant
This is a direct update on Cisco Secure Workload security issues, adding five newly patched CVEs in versions 4.0.4.16 and 3.10.9.1, including critical improper access control, authentication, command injection, and path traversal flaws beyond the previously tracked CVE-2026-20223.
Max severity Cisco Secure Workload flaw gives Site Admin privileges
Sergiu Gatlan 2026.05.21 98% relevant
This article covers the same Cisco Secure Workload event: disclosure and patching of CVE-2026-20223, an unauthenticated flaw in internal REST APIs that can grant Site Admin privileges across tenant boundaries. It adds affected/fixed versions, notes there are no workarounds, and says Cisco has not seen in-the-wild exploitation.
Cisco Patches Critical Vulnerability in Secure Workload
Ionut Arghire 2026.05.21 100% relevant
This article establishes a distinct new story centered on Cisco's disclosure and patching of CVE-2026-20223 in Secure Workload; it does not match any existing tracked event.
Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw
2026.05.21 99% relevant
This article covers the same Cisco Secure Workload vulnerability disclosure and patch event for CVE-2026-20223, adding reporting detail on cross-tenant impact, affected fixed versions (3.10.8.3 and 4.0.3.17), lack of workarounds, and that Cisco SaaS deployments were already patched.
← Back to all stories