logo

Critical 9.8 Webex Flaw Lets Attackers Impersonate Any User

ID: 628676c8-c41d-5f6a-b0b5-bd9ec06a5fd1

STIX ID: report--628676c8-c41d-5f6a-b0b5-bd9ec06a5fd1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

The report describes a critical SSO authentication vulnerability in Cisco Webex Services (CVE-2026-20184, CVSS 9.8) where improper certificate validation could allow unauthenticated remote attackers to impersonate any user; Cisco patched the backend but customers must manually upload a new IdP SAML certificate in Control Hub to fully remediate, and PSIRT reports no known public exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.