Cisco Secure Workload Authentication Bypass Site Admin | MSSP Advisory
High
DateMay 21, 2026
📋Executive Summary
Cisco patched a maximum-severity authentication bypass flaw (CVE-2024-20441) in Secure Workload that lets attackers gain Site Admin privileges without credentials. The vulnerability affects the web-based management interface and allows complete control over network segmentation policies and monitoring configurations. Attack requires network access to the management interface but no user interaction.
⚠️Why It Matters for MSSPs
Site Admin access to Cisco Secure Workload means attackers control your entire network segmentation strategy and can see all traffic flows across client environments. Your clients running this platform face complete visibility loss and policy manipulation, while your own monitoring capabilities get compromised if you use Secure Workload for client oversight.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.