Cisco is releasing updates to address a critical security vulnerability in its Secure Workload product. Multiple outlets report that the flaw is cataloged as CVE-2026-20223 and carries a CVSS score of 10.0, the maximum severity level. The problem relates to insufficient validation and authentication when processing requests to Secure Workload REST API endpoints.

According to the reporting, an attacker may be able to exploit the vulnerability remotely, including scenarios described as involving unauthenticated access, if they can reach the affected API endpoints and submit crafted requests. SecurityWeek additionally reports that successful exploitation could grant elevated capabilities, specifically Site Admin privileges. The Hacker News also describes the risk as enabling access to sensitive data.

Cisco’s response, as described by the sources, consists of rolling out patches intended to correct the authentication and input-validation weaknesses in the REST API components. The coverage emphasizes that the vulnerability impacts Secure Workload and that customers should apply the updates to reduce the risk of unauthorized access.