Cisco's Secure Workload Earns a Perfect 10, in the Wrong Sense

An unauthenticated REST API flaw rated CVSS 10.0 lets remote attackers help themselves to sensitive data. Cisco has issued fixes.

ThreatVectr Newsdesk· 2 min read
Cisco's Secure Workload Earns a Perfect 10, in the Wrong Sense
Share

Cisco has patched a maximum-severity flaw in its Secure Workload platform that lets an unauthenticated remote attacker reach sensitive data through the product's REST API. The vulnerability, CVE-2026-20223, carries a CVSS score of 10.0 and stems from insufficient validation and authentication on REST API endpoints.

The maths is unflattering. No credentials, no user interaction, network-reachable, and the prize is data inside a workload-protection product that organisations bought precisely because they wanted to know what was talking to what.

An attacker only needs to be able to send crafted requests to an affected appliance. There is no exploit code in the wild that Cisco has acknowledged so far, though the bar for weaponisation here is not high. A 10.0 with no auth requirement tends to attract attention quickly.

Secure Workload, the product formerly sold as Tetration, is pitched at segmentation and east-west visibility for data centres and cloud estates. The customer base skews towards regulated sectors, which is the part that matters: telemetry from those deployments routinely includes flow records, process inventories, and policy metadata that an attacker would find useful for the next stage of an intrusion.

Cisco rates the issue critical and says fixed software is available. Administrators should consult the Cisco Security Advisory for the affected train and the corresponding fixed release, and patch on the short timeline that a 10.0 deserves rather than the long one that quarterly change windows tend to produce.

No workarounds are listed. That, predictably, leaves patching as the only honest answer. Operators who expose the Secure Workload UI or API beyond a management network should treat exposure as the first thing to fix, not the second (a depressingly common configuration in environments that were meant to be segmented in the first place).

There is a quiet irony in a workload-segmentation product shipping a pre-auth API flaw. The job of the appliance is to assume the network is hostile. The appliance, it turns out, was also on the network.

And a CVSS 10.0 in a security product is not exactly a novelty this year. Cisco itself has shipped several. Defenders sceptical of the category have one more data point. Those who run the product have a weekend's worth of work.

No public exploitation. Yet.

© 2026 Threat Vectr