Post
CRITICAL

Cisco Patches Maximum-Severity Auth Bypass in Secure Workload

· vulnerability · cve · privilege-escalation

Cisco patched a maximum-severity vulnerability in Secure Workload (formerly Tetration) where insufficient validation and authentication in the REST API layer allows remote, unauthenticated attackers to obtain full Site Admin privileges — granting control over workload segmentation policy across the environment.

No credentials or prior access are required to trigger the flaw. Cisco released a fixed version; there is no workaround short of blocking REST API exposure to untrusted networks. Operators should patch immediately and audit recent Site Admin activity for signs of unauthorized access.