Cisco Webex Services Vulnerability Let Remote Attacker Impersonate Any User
ID: 993a6b52-2041-512f-b1ee-0cc233d3b50d
STIX ID: report--993a6b52-2041-512f-b1ee-0cc233d3b50d
Feed Name: cybersecurityNews.com
Threat Score
Cisco published a critical advisory for CVE-2026-20184 (CVSS 9.8) affecting Webex Services SSO: improper certificate validation in the SSO implementation (CWE-295) can allow unauthenticated remote attackers to bypass authentication and impersonate users. Cisco applied a backend patch but administrators must manually upload new SAML certificates in Webex Control Hub to remediate; no evidence of in-the-wild exploitation at the time of publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
