CRITICAL
Cisco Patches Maximum-Severity Auth Bypass in Secure Workload
Cisco patched a maximum-severity vulnerability in Secure Workload (formerly Tetration) where insufficient validation and authentication in the REST API layer allows remote, unauthenticated attackers to obtain full Site Admin privileges — granting control over workload segmentation policy across the environment.
No credentials or prior access are required to trigger the flaw. Cisco released a fixed version; there is no workaround short of blocking REST API exposure to untrusted networks. Operators should patch immediately and audit recent Site Admin activity for signs of unauthorized access.