Switch language한국어
Back to the list

Cisco Secure Workload vulnerability can be exploited via API call

TL;DR AI

Key summary

2 min read
  1. Cisco disclosed CVE-2026-20223, a critical Secure Workload flaw in internal REST API checks.

  2. An attacker could send crafted API requests to gain full Site Admin privileges without logging in.

  3. The issue affects Secure Workload SaaS and on-premises deployments, with no workaround available.

  4. Cisco says it found the bug internally and has no evidence of real-world exploitation; fixes are in specific releases.

Read the original