Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

May 31, 2026

Making Vulnerable Drivers Exploitable Without Hardware

May 31, 2026

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

May 31, 2026
Facebook X (Twitter) Instagram
Sunday, May 31
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access
News

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Team-CWDBy Team-CWDMay 31, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data.

Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints.

“An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint,” Cisco said. “A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user.”

The shortcoming impacts Cisco Secure Workload Cluster Software on SaaS and on-prem deployments, regardless of device configuration. Cisco said there are no workarounds that address the vulnerability.

The issue has been addressed in the following versions –

  • Cisco Secure Workload Release 3.9 and earlier (Migrate to a fixed release)
  • Cisco Secure Workload Release 3.10 (Fixed in 3.10.8.3)
  • Cisco Secure Workload Release 4.0 (Fixed in 4.0.3.17)

The networking equipment major said it found the vulnerability during internal security testing and that there is no evidence of it being exploited in the wild.

The disclosure comes a week after Cisco revealed that another maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller (CVE-2026-20182, CVSS score: 10.0) has been exploited by a threat actor known as UAT-8616 to gain unauthorized access to SD-WAN systems.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleShowboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Next Article CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
Team-CWD
  • Website

Related Posts

News

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

May 31, 2026
News

Making Vulnerable Drivers Exploitable Without Hardware

May 31, 2026
News

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

May 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How chatbots can help spread scams

October 14, 2025

Fixing trivial passwords is as easy as 123456

May 7, 2026

In memoriam: David Harley

November 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.