Cisco has released security updates to patch four critical vulnerabilities, including a fixed improper certificate validation flaw in the company's cloud-based Webex Services platform that requires further customer action. Webex Services is a customer experience platform that unifies communication across hybrid work environments, enabling team members to call, meet, and message each other from any location or device. Tracked as CVE-2026-20184, the Webex vulnerability was found in the single sign-on (SSO) integration with Control Hub (a web-based portal that helps IT admins manage Webex settings) and allows remote attackers with no privileges to impersonate any user. "Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token," Cisco explained in a Wednesday advisory. "A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services." While the company has already addressed this security flaw in the Cisco Webex service, it warned customers who use SSO integration that they must upload a new SAML certificate for their identity provider (IdP) to Control Hub to avoid service interruption. On Wednesday, the company also patched three critical security flaws (CVE-2026-20147, CVE-2026-20180, and CVE-2026-20186) in the Identity Services Engine (ISE) security policy management platform. Attackers could exploit these vulnerabilities...
Cisco says critical Webex Services flaw requires customer action
BleepingComputer
·Sergiu Gatlan
·Published Apr 16, 2026
·Updated
Affected Software
3 affected components
Cisco Webex Services
Cisco Identity Services Engine
Cisco Secure Firewall Management Center
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Cisco Webex Services that requires immediate customer action to address.
2
What security implications are discussed in the article?
The article highlights four critical vulnerabilities that could compromise the security of Cisco's cloud-based Webex Services.
3
What customers are affected by the Webex Services flaw?
Customers using Cisco Webex Services, Cisco Identity Services Engine, and Cisco Secure Firewall Management Center are affected.
4
What action is required from customers regarding the Webex Services flaw?
Customers are required to implement the security updates released by Cisco to mitigate the vulnerabilities.
5
Who is the vendor addressing the Webex Services vulnerabilities?
Cisco is the vendor addressing the security vulnerabilities in their Webex Services platform.