Cisco Secure Workload vulnerability can be exploited via API call

TL;DR AI
2 min readKey summary
Cisco disclosed CVE-2026-20223, a critical Secure Workload flaw in internal REST API checks.
An attacker could send crafted API requests to gain full Site Admin privileges without logging in.
The issue affects Secure Workload SaaS and on-premises deployments, with no workaround available.
Cisco says it found the bug internally and has no evidence of real-world exploitation; fixes are in specific releases.


