Back to feed
Dev.to
Dev.to
7/14/2026
Cisco Patches CVSS 10.0 Flaw in Secure Workload — Unauthenticated Attackers Could Gain Site Admin via API

Cisco Patches CVSS 10.0 Flaw in Secure Workload — Unauthenticated Attackers Could Gain Site Admin via API

Short summary

Cisco has issued emergency patches for CVE-2026-20223, a CVSS 10.0 vulnerability in Secure Workload (formerly Tetration) that lets unauthenticated attackers gain Site Admin privileges via crafted REST API requests. The flaw affects both SaaS and on-premises deployments, with no workarounds available. Exploitation could allow cross-tenant access, policy modification, and lateral movement across enterprise networks.

  • CVE-2026-20223: CVSS 10.0 flaw in Cisco Secure Workload allows unauthenticated Site Admin access via API
  • Affects both SaaS and on-premises deployments; no workarounds exist
  • Patch immediately — exploitation could enable cross-tenant access and lateral movement

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more