logo

Cisco Webex Services Vulnerability Let Remote Attacker Impersonate Any User

ID: 993a6b52-2041-512f-b1ee-0cc233d3b50d

STIX ID: report--993a6b52-2041-512f-b1ee-0cc233d3b50d

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Abinaya

...
...

Cisco published a critical advisory for CVE-2026-20184 (CVSS 9.8) affecting Webex Services SSO: improper certificate validation in the SSO implementation (CWE-295) can allow unauthenticated remote attackers to bypass authentication and impersonate users. Cisco applied a backend patch but administrators must manually upload new SAML certificates in Webex Control Hub to remediate; no evidence of in-the-wild exploitation at the time of publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.