惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
小众软件
小众软件
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
博客园 - 三生石上(FineUI控件)
博客园_首页
N
Netflix TechBlog - Medium
IT之家
IT之家
H
Help Net Security
博客园 - 聂微东
Google DeepMind News
Google DeepMind News
罗磊的独立博客
T
Tailwind CSS Blog
F
Fortinet All Blogs
Hugging Face - Blog
Hugging Face - Blog
MongoDB | Blog
MongoDB | Blog
V
V2EX
量子位
云风的 BLOG
云风的 BLOG
爱范儿
爱范儿
博客园 - 司徒正美
The Cloudflare Blog
Engineering at Meta
Engineering at Meta

Truesec

The Ryde Data Breach - Truesec CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Securing IT, OT, and IoT When the Digital Meets the Physical
Critical Cisco Secure Workload Vulnerability Allows Unaut...
Hjalmar Desmond · 2026-05-22 · via Truesec

Threat Insight

Cisco has released security updates addressing a critical vulnerability, CVE-2026-20223, in Cisco Secure Workload. The vulnerability has a CVSS base score of 10.0 and could allow an unauthenticated remote attacker to gain Site Admin privileges by abusing internal REST API endpoints.

The vulnerability is caused by insufficient validation and authentication for internal REST API endpoints. An attacker could exploit the issue by sending a crafted API request to a vulnerable endpoint without authentication.

Successful exploitation could allow an attacker to:

  • Access site resources with Site Admin privileges
  • Read sensitive information
  • Modify configuration data across tenant boundaries
  • The vulnerability affects Cisco Secure Workload Cluster Software in both SaaS and on-premises environments, regardless of device configuration. Cisco states that the issue affects only internal REST APIs and does not impact the web-based management interface.

Cisco has released fixed software versions to remediate the issue. No workarounds are available, and customers are strongly advised to upgrade to a fixed release as outlined in the advisory.

Affected Products

Cisco Secure Workload Release 3.10
Cisco Secure Workload Release 3.9 and earlier
Cisco Secure Workload Release 4.0

Exploitation

The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability according to their advisory[1].

Recommended Actions

Truesec recommends that you apply fixes according to the table provided by Cisco, see below:

  • Cisco Secure Workload Release 3.9 and earlier – Migrate to a fixed release
  • Cisco Secure Workload Release 3.10 – Fixed in 3.10.8.3
  • Cisco Secure Workload Release 4.0 – Fixed in 4.0.3.17

There are no mitigations available.

References

[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy