Dev.to
7/14/2026

Cisco Patches CVSS 10.0 Flaw in Secure Workload — Unauthenticated Attackers Could Gain Site Admin via API
Short summary
Cisco has issued emergency patches for CVE-2026-20223, a CVSS 10.0 vulnerability in Secure Workload (formerly Tetration) that lets unauthenticated attackers gain Site Admin privileges via crafted REST API requests. The flaw affects both SaaS and on-premises deployments, with no workarounds available. Exploitation could allow cross-tenant access, policy modification, and lateral movement across enterprise networks.
- •CVE-2026-20223: CVSS 10.0 flaw in Cisco Secure Workload allows unauthenticated Site Admin access via API
- •Affects both SaaS and on-premises deployments; no workarounds exist
- •Patch immediately — exploitation could enable cross-tenant access and lateral movement
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



