Cisco Secure Workload Flaw Demands Immediate Attention

Cisco Secure Workload vulnerability allows attackers admin-level access; patch now.

ThreatVectr Newsdesk· 2 min read
Cisco Secure Workload Flaw Demands Immediate Attention
Share

San Jose, Calif. — Cisco identified a critical flaw in its Secure Workload platform. This vulnerability allows remote attackers to gain site admin privileges without authentication, Cisco's advisory said. It affects the on-premises version and scored a maximum 10.0 on the CVSS scale.

By exploiting the vulnerability, identified as CVE-2026-20223, attackers can bypass authentication through a crafted HTTP request to an internal REST API. Consultant Robert Enderle of the Enderle Group said CSOs should prioritize patching, noting the platform's role in zero trust and micro-segmentation.

"If an attacker controls this platform, they own your network," Enderle said. Fred Chagnon, principal research director at Info-Tech Research Group, echoed the urgency. He highlighted the risk of modifying or dismantling security policies, potentially affecting multi-tenant deployments.

Cisco recommends updating systems to version 4.0.3.17 for those on version 4.0, or 3.10.8.3 for version 3.10. Older versions should upgrade to the nearest fixed release. No workarounds exist; only the on-premises product requires action, as Cisco has patched the SaaS version.

Cisco's team discovered and disclosed the vulnerability, publishing a patch simultaneously. No exploitation in the wild has been detected, Chagnon said. Despite this, organizations should treat it as an active threat due to its severity.

In April, Cisco addressed another critical vulnerability in Webex Control Hub. A similar patch was issued in January for Unified Communications Manager and related products. A China-linked group exploited a Secure Email appliance flaw last December, Cisco warned. The next step for administrators is immediate patch implementation.

© 2026 Threat Vectr