logo

Cisco fixed four critical flaws in Identity Services and Webex

ID: 62383c19-df3d-52ba-ad6d-f350f2f104ab

STIX ID: report--62383c19-df3d-52ba-ad6d-f350f2f104ab

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco released patches for four critical vulnerabilities in Webex and Identity Services Engine (ISE): CVE-2026-20184 (Webex SSO certificate validation allowing impersonation, CVSS 9.8), CVE-2026-20147 (ISE input validation permitting remote code execution, CVSS 9.9), and CVE-2026-20180/CVE-2026-20186 (ISE input validation enabling OS command execution with read-only admin access, CVSS 9.9). Cisco states there is no evidence of public disclosure or active exploitation and urges urgent updates to mitigate potential unauthorized access and code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.