Back Beyondmachines Cisco Patches Critical CVSS 10.0 Authentication Bypass in Secure Workload
Advisory Cisco Patches Critical CVSS 10.0 Authentication Bypass in Secure Workload
Take action: Make sure your Cisco Secure Workload clusters are isolated from the internet and accessible only from trusted networks. If you run on-premises Cisco Secure Workload, immediately update to version 3.10.8.3 or 4.0.3.17 to patch CVE-2026-20223; if you're on versions 3.9 or older, plan a migration to a supported patched release since no direct updates are available.
Cisco reports a critical vulnerability in its Secure Workload platform, affecting both cloud-based SaaS and on-premises cluster software. The flaw allows unauthenticated attackers to gain full administrative control over the system
The flaw is tracked as CVE-2026-20223 (CVSS score 10.0) - A missing authentication vulnerability in the internal REST API endpoints of Cisco Secure Workload Cluster Software that allows unauthenticated remote access. Attackers can trigger the flaw by sending specially crafted API requests to affected internal endpoints that lack proper validation checks. Successful exploitation grants the attacker Site Admin privileges, enabling them to read sensitive data or modify system configurations across different tenant environments.
This security issue affects Cisco Secure Workload Cluster Software on all deployment types, including SaaS and on-premises installations:
Cisco has already applied patches to its cloud-based SaaS environments, so those customers do not need to take manual action.
Administrators of on-premises deployments must immediately update to version 3.10.8.3 or 4.0.3.17 to secure their systems.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
