logo

Cisco says critical Webex Services flaw requires customer action

ID: b0f76b79-d551-51b5-98da-dde4ebc9639e

STIX ID: report--b0f76b79-d551-51b5-98da-dde4ebc9639e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco released security updates addressing multiple critical vulnerabilities — notably a Webex SSO improper certificate validation flaw (CVE-2026-20184) that could allow remote, unauthenticated user impersonation and several critical Identity Services Engine (ISE) issues; administrators using SSO must upload a new SAML certificate to Control Hub to avoid disruption. Cisco stated it has no evidence the newly patched flaws were exploited, but the report also references a distinct maximum-severity Secure Firewall FMC vulnerability that was exploited in the wild by Interlock ransomware, which prompted a CISA patch directive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.