Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
ID: d2ce16a7-98c8-5d16-a9f8-7a71d75adbe5
STIX ID: report--d2ce16a7-98c8-5d16-a9f8-7a71d75adbe5
Feed Name: The Hacker News
Cisco released patches for four critical vulnerabilities affecting Webex Services and Identity Services Engine (ISE) — including a cloud-side SSO certificate validation issue enabling user impersonation (CVE-2026-20184) and multiple insufficient input validation flaws in ISE that could allow authenticated attackers to execute arbitrary commands or achieve remote code execution (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186). All issues carry very high CVSS scores (9.8–9.9); Cisco provided fixed releases/patches for affected ISE versions, advised SSO customers to upload a new IdP SAML certificate, and stated it is not aware of active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
