Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
identity-authentication-vulnerabilitywidely-deployed-product-advisorycloud-service-vulnerabilityinternet-facing-service-vulnerability

Critical Cisco Secure Workload API Flaw Grants Unauthenticated Site Admin Access

Updated 1d agoFirst seen May 21, 202612 sources

Cisco disclosed CVE-2026-20223, a critical CVSS 10.0 vulnerability in Cisco Secure Workload Cluster Software that allows an unauthenticated remote attacker to gain Site Admin privileges by sending crafted requests to internal REST API endpoints. The flaw stems from insufficient authentication and access validation (CWE-306) and affects both SaaS and on-premises deployments, enabling access to site resources, exposure of sensitive information, and configuration changes that can cross tenant boundaries.

Cisco said its hosted SaaS environments have already been remediated, while customers running affected versions must upgrade because no workaround is available. Fixed releases include 3.10.8.3 and 4.0.3.17, with the issue affecting version 3.9 and earlier, versions before 3.10.8.3, and versions before 4.0.3.17. Cisco and the Canadian Centre for Cyber Security urged administrators to review the advisory and apply updates promptly; Cisco said it is not aware of active exploitation and reported that the vulnerability was identified during internal security testing.

Share:
Critical Cisco Secure Workload API Flaw Grants Unauthenticated Site Admin Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
May 20, 20261mo ago

Canadian Centre for Cyber Security urges users to apply Cisco updates

The Canadian Centre for Cyber Security issued advisory AV26-491 highlighting Cisco's May 20 security advisories and specifically calling attention to the critical Cisco Secure Workload issue. It urged administrators to review Cisco's guidance and apply the necessary updates.

Cisco releases fixed Secure Workload versions and patches SaaS deployments

Cisco made fixes available for affected on-premises deployments in versions 3.10.8.3 and 4.0.3.17, with no workaround provided. Cisco also stated that its hosted SaaS environments had already been remediated and that it was not aware of active exploitation.

Cisco publishes advisory for CVE-2026-20223 in Secure Workload

Cisco disclosed CVE-2026-20223, a critical unauthorized API access vulnerability in Cisco Secure Workload caused by insufficient validation and authentication on internal REST API endpoints. The flaw can let an unauthenticated remote attacker gain Site Admin privileges, access sensitive information, and make configuration changes across tenant boundaries.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Nginx
Organizations
9 linked
Cisco SystemsAmazon Web ServicesRapid7ColorTokensThe Cyber ExpressSecurity AffairsdepthfirstSuzu LabsCourser
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Cisco Secure Workload API Flaw Grants Unauthenticated Site Admin Access | Mallory