INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco Patch Fixes CVSS 10.0 Flaw in Secure Workload

| 2026-05-22 05:36 CRITICAL HIGH
Executive Summary AI-generated
The vulnerability, dubbed Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access, has been identified in the latest versions of Cisco's Secure Workload software. This issue arises from insufficient validation and authentication when accessing REST API endpoints, allowing an unauthenticated attacker to access sensitive data with elevated privileges. The vulnerability was first reported on May 22, 2026, by a threat actor known as UAT-8616, who exploited it just one week after Cisco revealed another maximum-severity authentication bypass flaw in its Catalyst SD-WAN Controller. This latest disclosure highlights the importance of timely software updates to prevent exploitation and maintain network security.
Technical Mitigations AI-generated
* Implement robust authentication and authorization mechanisms: Ensure that all users, including Site Admins, have strong passwords and multi-factor authentication enabled to prevent unauthorized access. * Validate API requests thoroughly: Implement a validation mechanism for REST API endpoints to ensure that only authorized requests are allowed. This can include checking user permissions, IP addresses, or other factors before granting access. * Use secure communication protocols (e.g., HTTPS): Ensure that all communications between the client and server use secure protocols like HTTPS to prevent eavesdropping and tampering with sensitive data. * Regularly update software and firmware: Keep Cisco Secure Workload Cluster Software up-to-date with the latest security patches, including CVSS scores of 10.0 or higher, to ensure that known vulnerabilities are addressed before they can be exploited by attackers. Note: These mitigations may not completely prevent exploitation of a specific vulnerability like CVE-2026-20182, but rather help reduce its likelihood and impact.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20223CVE-2026-20223 CVE-2026-20182CVE-2026-20182
Target & Sectors
Global Scope
Incident Timeline
‎May 14
Threat actors exploited the Cisco Secure Workload flaw CVE-2026-00123 to gain Site Admin privileges.
vulnerability CVE-2026-20182
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎May 17
Threat actors exploited the Cisco Secure Workload flaw CVE-2026-00123 to gain Site Admin privileges.
vulnerability CVE-2026-20182
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎May 22, 2026
Threat actors exploited a vulnerability in Cisco Secure Workload to gain unauthorized access to sensitive data.
organisation Vulnerability / Network Security
‎2026/05/22
Cisco fixed a critical Secure Workload flaw (CVE-2026-20223) that could let attackers gain Site Admin privileges through crafted API requests.
organisation API Flaw Enabling Data Access
infrastructure 10.0
organisation Secure Workload's
organisation API
organisation Secure Workload
organisation SecurityAffairs
infrastructure 3.9
organisation Migrate
infrastructure 3.10
infrastructure 3.10.8
organisation Cisco Secure Workload Release
infrastructure 4.0.3
organisation Product Security Incident Response Team
infrastructure 4.0
organisation Catalyst SD-WAN Controller
organisation CVSS
organisation SD-WAN
organisation Cisco
organisation Catalyst SD-WAN
organisation Site Admin
organisation Cisco Secure Workload
organisation Cisco Tetration
organisation the Secure Workload
organisation DoS
organisation Crosswork Network Controller
organisation Network Services Orchestrator
organisation NSO
organisation Cisco Product Security Incident Response Team
Tactical Metrics
Metrics
infrastructure
‎3.9
Software Version
Metrics
infrastructure
‎3.10
Software Version
Metrics
infrastructure
‎3.10.8
Software Version
Metrics
infrastructure
‎4.0
Software Version
Metrics
infrastructure
‎4.0.3
Software Version
Metrics
infrastructure
‎10.0
Software Version
Intelligence Sources