PatchDay Alert

CVE

CVE-2026-20223

0field notes · 1digest CVSS 10.0


Daily digests

An unauthenticated remote attacker can hit internal REST APIs on Cisco Secure Workload and get full Site Admin privileges. That means reading sensitive data and changing configuration across tenant boundaries, no credentials required. This is a CVSS 10.0 for good reason: no auth, no user interaction, full cross-tenant control.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.