CVE-2026-20223Patch(cisco / secure_workload)

CRITICALCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 19 mentions and remains active

Immediate actions

  • Patch cisco secure_workload systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • secure_workload

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 59 mentions across 10 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 37 signals
  • Technical details provided in 45 signals
  • Disclosure: 13 classified signals
  • General: 6 classified signals
  • Peaked 8d ago at 19 mentions (2026-05-21); latest day: 1
  • 59 total mentions across 10 days

Affected systems

Vendors
Products
secure_workload

Deep dive

Activity timeline59 mentions / 10d
05101419Mentions · 2026-05-20: 3Mentions · 2026-05-21: 19Mentions · 2026-05-22: 19Mentions · 2026-05-23: 6Mentions · 2026-05-24: 1Mentions · 2026-05-25: 2Mentions · 2026-05-26: 3Mentions · 2026-05-27: 3Mentions · 2026-06-07: 2Mentions · 2026-06-09: 1PoC Mentioned / Linked · 2026-05-22: 3Exploit Tool / Code · 2026-05-22: 1Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-05-22: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 13Patch / Workaround · 2026-05-22: 11Patch / Workaround · 2026-05-23: 3Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-25: 2Patch / Workaround · 2026-05-26: 3Patch / Workaround · 2026-05-27: 2Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 14Technical Details · 2026-05-22: 14Technical Details · 2026-05-23: 4Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 2Technical Details · 2026-05-26: 3Technical Details · 2026-05-27: 3Technical Details · 2026-06-07: 1Technical Details · 2026-06-09: 105-2005-2105-2205-2305-2405-2505-2605-2706-0706-09
Signal classification5 categories
Patch
3355.9%
Disclosure
1322.0%
General
610.2%
Active Exploitation
46.8%
PoC
35.1%
Referenced assets38 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-203
Disclosure1General1Patch1
2026-05-2119
Active Exploitation2Disclosure3General1Patch13
2026-05-2219
Active Exploitation1Disclosure4General1Patch10PoC3
2026-05-236
Active Exploitation1Disclosure1General2Patch2
2026-05-241
Disclosure1
2026-05-252
Patch2
2026-05-263
Disclosure1Patch2
2026-05-273
Disclosure1Patch2
2026-06-072
Disclosure1General1
2026-06-091
Patch1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    🚨 Critical Alert: Cisco Secure Workload Hit with CVSS 10.0 Flaw. https://thehackernews.com/2026/05/cisco-patches-cvss-100-secure-workload.html Unauthenticated attackers can exploit a REST API vulnerability (CVE-2026-20223) to steal sensitive data and make configuration changes across tenant boundaries with Site Admin privileges. Affects both SaaS and on-prem deployments. No workarounds. Patch immediately: • 3.10 → 3.10.8.3 • 4.0 → 4.0.3.17 • 3.9 or older → Migrate now

    Post summary

    The alert reports a CVSS 10.0 REST API flaw (CVE‑2026‑20223) in Cisco Secure Workload, emphasizing immediate patching to prevent unauthenticated cross‑tenant data access and configuration changes.

    46261534524.9K
    1.9M followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    "سيسكو تبيع منتج لـ Zero Trust وMicrosegmentation عشان تصعب الحركة غير المصرح بها في الشبكه على المهاجم وبعدين تطلع ثغرة تسوي العكس وتسهل على المهاجم الحركه في الشبكه 😆 المنتج Cisco Secure Workload (Tetration) التقييم CVSS 10.0 الثغرة رقمها (CVE-2026-20223) https://t.co/xHB9ZqRVfo

    Post summary

    The tweet announces CVE‑2026‑20223 for Cisco Secure Workload (Tetration) with a CVSS of 10.0, but provides no exploitation or mitigation details.

    24037244.1K
    50.0K followersView on X
  • Azubuike Ibe@ai_dev_official
    Patch

    Cisco just patched a CVSS 10.0 flaw in Secure Workload. CVE-2026-20223. Unauthenticated remote attackers could gain Site Admin-level access through internal REST APIs. Maximum severity. No credentials required. The flaw affects both SaaS and on-prem deployments. Successful exploitation exposes workload telemetry, segmentation policies, and configuration data. In the wrong hands, that is a blueprint for lateral movement across your entire management plane. Here is the pattern I keep seeing in production environments. Teams apply rigorous security controls to their internet-facing APIs. Auth, rate limiting, input validation, the full stack. Then internal APIs and management tools get treated as trusted by default because they are behind the perimeter. Attackers know this. It is one of the first things they probe after initial access. Management plane infrastructure is not internal in any meaningful security sense anymore. It is high-value real estate. And a CVSS 10.0 in a tool like Secure Workload confirms exactly that. Strict authentication on every API endpoint. Least-privilege access enforced at the service level. Rate limiting and input validation applied uniformly. Network segmentation around your management layer. Continuous auditing of API access logs. Not optional. Not aspirational. Default baseline in 2026. My name is Azubuike Ibe and I write about this because the assumption that internal means trusted is one of the most expensive mistakes a backend team can make. When did you last audit your internal APIs and management tooling for this kind of exposure? #Cybersecurity #Cisco #APISecurity #DevSecOps #AppSec

    Post summary

    Cisco has issued a patch for CVE‑2026‑20223, a CVSS 10.0 unauthenticated flaw in Secure Workload that allows Site Admin access via internal REST APIs. The post warns of the critical need for robust authentication and monitoring of internal management interfaces.

    03087117
    1.5K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na kritickou zranitelnost v Cisco Secure Workload, CVE-2026-20223 s CVSS skóre 10. Zranitelnost je způsobena nedostatečnou validací a autentizací interních REST API endpointů, což umožňuje neautentizovanému vzdálenému útočníkovi zasílat speciálně vytvořené API požadavky a získat přístup s oprávněními Site Admin. Úspěšné zneužití může vést k neoprávněnému přístupu k citlivým datům, porušení izolace tenantů a neautorizovaným změnám konfigurace v prostředí. Zranitelnost se týká SaaS i on‑premises nasazení Cisco Secure Workload ve verzích 3.9 a starších, 3.10 a 4.0. 📌Doporučujeme aktualizovat Cisco Secure Workload 3.10 na verzi 3.10.8.3, Cisco Secure Workload 4.0 na verzi 4.0.3.17 a u verzí 3.9 a starších provést upgrade na podporovanou opravenou verzi.

    Post summary

    CVE‑2026‑20223 is a critical flaw in Cisco Secure Workload that lets unauthenticated attackers elevate to Site Admin via crafted API calls; the vendor recommends upgrading to patched versions to mitigate the risk.

    12070589
    4.2K followersView on X
  • Rosetta Porter 🕊️🦄@sindarin_0
    PoC

    CVE-2026-20223 PoC. A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. "Educational Purposes Only" https://github.com/HORKimhab/CVE-2026-20223

    Post summary

    The post announces a proof‑of‑concept for CVE-2026-20223, revealing an unauthenticated remote privilege escalation in Cisco Secure Workload’s internal REST APIs, but it does not mention active exploitation, patch availability, or a detailed functional exploit.

    02043563
    824 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    Cisco Secure Workload Unauthorized API Access Vulnerability(CVE-2026-20223) https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy 『(直訳)Cisco Secure Workloadの内部REST APIのアクセス検証における脆弱性により、認証されていないリモート攻撃者がサイト管理者権限でサイトリソースにアクセスできる可能性があります。この脆弱性は、REST APIエンドポイントへのアクセス時に検証と認証が不十分であることに起因します。』 【セキュリティ ニュース】ワークロード保護製品「Cisco Secure Workload」に深刻な脆弱性(1ページ目 / 全1ページ):Security NEXT https://www.security-next.com/184720

    Post summary

    The advisory announces a new CVE (CVE-2026-20223) describing an unauthorized API access flaw that permits unauthenticated remote attackers to obtain site administrator privileges. No PoC, exploit, or active exploitation claim is made.

    000321.1K
    11.7K followersView on X
  • Cyber News Live@cybernewslive
    Disclosure

    Cisco has disclosed a maximum-severity security flaw (CVE-2026-20223) in a widely used enterprise platform that lets an attacker break in without any username or password — just by sending a specially crafted request to an internal API endpoint (a connection point the software uses to receive instructions). Once in, the attacker gains the highest level of admin access, can rewrite or delete security policies, and in shared environments may be able to reach data belonging to multiple organisations at once. Security researchers warn attackers are already scanning for unpatched systems. If your employer uses Cisco enterprise software, forward this to your IT team immediately and ask them to confirm whether CVE-2026-20223 has been patched. 🔥 #CyberNewsLive https://csoonline.com/article/4175913/critical-vulnerability-in-cisco-secure-workload-rated-at-maximum-severity.html

    Post summary

    Cisco reveals CVE‑2026‑20223 as a maximum‑severity vulnerability granting full admin access through a crafted API request; researchers warn of scanning for unpatched systems, but no exploit or patch details are referenced.

    01002184
    2.1K followersView on X
  • BrainLabVisions@BrainLabVisions
    PoC

    Cisco just disclosed a critical CVSS 10.0 vulnerability in Secure Workload (CVE-2026-20223). Unauthenticated attackers can hijack Site Admin privileges, steal sensitive data, and move across tenants — with zero workarounds available. WEBOUNCER by http://Kralos.eu 🦾🦾 https://t.co/XfjIVcDwLL

    Post summary

    Cisco disclosed CVE-2026-20223, a CVSS‑10 critical flaw allowing unauthenticated privilege escalation and tenant‑crossing data theft; zero mitigations are available, and a PoC/weaponized tool (WEBOUNCER) is linked for exploitation.

    0012098
    58 followersView on X
  • PurpleOps@PurpleOps_io
    PoC

    CVE-2026-20223 PoC: unauth GET to /api/v1/users confirms the target, then POST creates a Site Admin account. That account persists through patching unless audited. Detection: new Site Admin with no preceding auth log. Send this to your patching team. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy https://t.co/XXbXbnujif

    Post summary

    A PoC for CVE‑2026‑20223 demonstrates an unauthenticated API exploit to create a persistent Site Admin account; the post urges patching, citing a Cisco advisory link.

    00021234
    605 followersView on X
  • Anavem.com@Anavem_
    Patch

    Cisco Patches Critical CVE-2026-20223 in Secure Workload #cve202620223 #ciscosecureworkload #authenticationbypass https://www.anavem.com/en/news/cybersecurity/cisco-patches-critical-cve-2026-20223-in-secure-workload

    Post summary

    Cisco has issued a patch for the critical authentication bypass vulnerability CVE-2026-20223 in Secure Workload.

    01020207
    158 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Cisco Secure WorkloadにCVSSスコア10の脆弱性。CVE-2026-20223は内部REST APIのアクセス検証不備で、サイト管理者権限でリソースにアクセス可能。マルチテナント環境ではテナント境界越えが可能。Release 3.10と4.10は修正あり。3.9以前はインフラ移行を。 https://securityonline.info/cisco-secure-workload-api-vulnerability-cve-2026-20223-cvess-10/

    Post summary

    Cisco Secure Workload suffers a critical CVE‑2026‑20223 that allows administrative and cross‑tenant REST API access; fixes are available in releases 3.10 and 4.10.

    00012825
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Cisco drops an urgent advisory for CVE-2026-20223 (CVSS 10.0) in Secure Workload. Unauthenticated remote attackers can steal full Site Admin privileges. #CiscoSecurity #CVE #CVSS10 #ZeroTrust #CloudSecurity #Microsegmentation #InfoSec #CyberSecurity https://securityonline.info/cisco-secure-workload-api-vulnerability-cve-2026-20223-cvess-10/ https://t.co/9q8ZsfZUNS

    Post summary

    Cisco released an urgent advisory for the high‑severity CVE‑2026‑20223 in Secure Workload, detailing that unauthenticated remote attackers can gain full Site Admin rights. No exploit code, PoC, or patch information is provided in the tweet.

    00021494
    12.5K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-20223 — CVSS 10/10 ██████████ A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/RabcQfeGrO

    Post summary

    The tweet announces a critical CVE for Cisco Secure Workload, indicates the vulnerability pertains to REST API access validation, and confirms that a patch is available, with no mention of PoC, exploit code, or ongoing exploitation.

    11010150
    42 followersView on X
  • كاسبر سكاي@KasperskyDev
    Disclosure

    🔴 CVE-2026-20223 في Cisco Secure Workload - CVSS 10.0 Critical. مهاجم غير مصادق يرسل طلب HTTP واحداً للـ REST API الداخلي فيحصل على صلاحيات Site Admin كاملة عبر حدود الـ tenant. Fix: 3.10.8.3 و4.0.3.17. لا workarounds. #CVE-2026-20223 #CiscoSecurity

    Post summary

    Cisco Secure Workload vulnerability CVE-2026-20223, rated CVSS 10.0 critical, allows an unauthenticated attacker to use one HTTP request to the internal REST API to gain full Site Admin privileges across tenant boundaries; patches 3.10.8.3 and 4.0.3.17 are recommended.

    10010209
    40.0K followersView on X
  • CloudSecurityAlliance@cloudsa
    Active Exploitation

    CISO Daily Briefing: Cisco Secure Workload CVE-2026-20223 (CVSS 10.0) REST API auth bypass and SonicWall VPN MFA bypass are active ransomware vectors — patch or isolate now; CISA and Five Eyes issued joint guidance on agentic AI privilege creep and audit gaps; the AI SDK/orchestration monoculture means a single supply chain campaign now reaches your entire AI pipeline simultaneously. https://labs.cloudsecurityalliance.org/research/ciso-daily-briefing-20260522/

    Post summary

    The briefing highlights that CVE-2026-20223 is actively exploited as a ransomware vector, urges immediate patching or isolation, and notes the high CVSS score and specific bypass mechanisms.

    01010379
    18.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2016-5195 3 - CVE-2026-20223 4 - CVE-2026-41940 5 - CVE-2026-41089 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A short list of trending CVE identifiers without additional technical or operational context.

    00020755
    1.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Cisco Patches Critical CVSS 10.0 Secure Workload Vulnerability Cisco released fixes for CVE-2026-20223, a maximum-severity flaw in Secure Workload caused by insufficient validation/authentication in REST API endpoints. Successful exploitation could allow: • unauthenticated access • sensitive data exposure • cross-tenant configuration changes • Site Admin-level privileges No workarounds are available - affected SaaS and on-prem deployments should apply Cisco’s fixes immediately.

    Post summary

    Cisco issues critical patches for CVE-2026-20223, a flaw that allows unauthenticated access and cross‑tenant changes; immediate application of fixes is recommended.

    00020150
    196 followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Cisco CVSS 10.0 CVE-2026-20223. CVSS 10.0. Cisco Secure Workload's internal REST APIs fail to validate access unauthenticated remote attacker gets full Site Admin privileges. No exploit complexity. No user interaction. Patch available now. Source: BleepingComputer / Cisco Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Cisco Secure Workload’s CVE‑2026‑20223 allows unauthenticated attackers to gain full Site Admin privileges; a critical 10.0 CVSS, but a patch is already available.

    01010104
    182 followersView on X
  • SOCRadar®@socradar
    Disclosure

    A CVSS 10.0 is like leaving the vault door wide open. 🚨 CVE-2026-20223 in Cisco Secure Workload allows remote, unauthenticated attackers to grab Site Admin privileges via an API auth bypass. Treat this as urgent to mitigate your risk today. 👇 https://hubs.la/Q04hDLKd0 #Cisco #CyberSecurity #AuthBypass

    Post summary

    A newly disclosed, high‑severity vulnerability (CVE‑2026‑20223) in Cisco Secure Workload allows remote, unauthenticated attackers to bypass API authentication and obtain Site Admin rights.

    00011209
    5.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2026-20223 to gain Site Admin privileges on Cisco Secure Workload without authentication. The flaw enabled cross-tenant access and lateral movement within networks. Runtime segmentation helps contain such privilege escalation attacks. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisco-secure-workload-cve-2026-20223

    Post summary

    The post reports that CVE‑2026‑20223 has been actively exploited to gain Site Admin privileges and enable cross‑tenant lateral movement in Cisco Secure Workload, with no mitigation or PoC details provided.

    1001087
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_workload---

Explore more