A critical vulnerability in the on-premises version of the Cisco Secure Workload could allow a malicious user to gain the privileges of a site administrator, compromise endpoints , and read or modify configuration data.

“CSOs need to drop what they’re doing and apply the patch immediately,” warned consultant Robert Enderle, principal at Enderle Group. “Cisco Secure Workload manages zero trust, micro-segmentation , and network visibility across the enterprise. If an attacker controls the platform that defines your security policies, they essentially own the map and keys to your network. That’s the absolute worst-case scenario,” he added.
See also: Windows Alert: Zero-day exploit in Microsoft Defender
“Due to the vital importance of this platform, malicious users will aggressively scan for outdated API endpoints to exploit“.
The urgency to address the issue was also highlighted by Fred Chagnon, principal research director at Info-Tech Research Group. An attacker could modify or subvert an organization's security, opening doors into the environment that had been intentionally closed.
“Because this access operates at the site administrator level and crosses tenant boundaries, the blast radius in a multi-tenant deployment could be significant, potentially exposing or compromising workloads and data belonging to multiple business units or customers“.

Cisco Secure Workload: Vulnerability CVE-2026-20223
Cisco rated the vulnerability (CVE-2026-20223) with CVSS 10.0 because it allows an unauthenticated, remote attacker to completely bypass authentication.
See also: CISA adds 7 vulnerabilities to the KEV List
By sending a crafted HTTP request to an internal REST API endpoint, the malicious user immediately gains administrator privileges site. In its announcement, Cisco says that this hole is due to insufficient validation and authentication when accessing REST API endpoints.
Cisco: Security updates to address the issue
There are no workarounds. The only solution is to install software updates to address this vulnerability, which Cisco “strongly recommends”:
- Systems running version 4.0 should be upgraded to 4.0.3.17.
- Those with version 3.10 should upgrade to 3.10.8.3.
- Those still on version 3.9 and older should upgrade to a newer, fixed version.

The vulnerability affects Secure Workload Cluster Software in both SaaS and on-prem deployments, regardless of device configuration, but only affects internal REST APIs and does not affect the web-based management interface.
However, only those using the on-prem version need to take action. Cisco has already patched the SaaS product.
See also: 9-year-old Linux Kernel vulnerability allows root access
As of Wednesday, Cisco was not aware of any malicious use of the vulnerability.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The good news is that Cisco's own security team discovered and disclosed this vulnerability, releasing a patch at the same time as the announcement.
While the SaaS version of the platform has already been patched by Cisco, administrators running Cisco Secure Workload on-premises should not treat this as something that needs to be patched during the regular update cycle.
“Given the nature of this vulnerability, its CVSS score, no authentication required, and no available workaround, organizations should treat it as they would an active threat,” he said.
