• News/
  • https://www.bleepingcomputer.com/news/security/cisco-says-critical-webex-services-flaw-requires-customer-action/

Cisco says critical Webex Services flaw requires customer action

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 16, 2026
·
Updated

Cisco has released security updates to patch four critical vulnerabilities, including a fixed improper certificate validation flaw in the company's cloud-based Webex Services platform that requires further customer action. Webex Services is a customer experience platform that unifies communication across hybrid work environments, enabling team members to call, meet, and message each other from any location or device. Tracked as CVE-2026-20184, the Webex vulnerability was found in the single sign-on (SSO) integration with Control Hub (a web-based portal that helps IT admins manage Webex settings) and allows remote attackers with no privileges to impersonate any user. "Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token," Cisco explained in a Wednesday advisory. "A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services." While the company has already addressed this security flaw in the Cisco Webex service, it warned customers who use SSO integration that they must upload a new SAML certificate for their identity provider (IdP) to Control Hub to avoid service interruption. On Wednesday, the company also patched three critical security flaws (CVE-2026-20147, CVE-2026-20180, and CVE-2026-20186) in the Identity Services Engine (ISE) security policy management platform. Attackers could exploit these vulnerabilities...

Read full article

Affected Software

3 affected components
Cisco Webex Services
Cisco Identity Services Engine
Cisco Secure Firewall Management Center
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Cisco Webex Services that requires immediate customer action to address.

2

What security implications are discussed in the article?

The article highlights four critical vulnerabilities that could compromise the security of Cisco's cloud-based Webex Services.

3

What customers are affected by the Webex Services flaw?

Customers using Cisco Webex Services, Cisco Identity Services Engine, and Cisco Secure Firewall Management Center are affected.

4

What action is required from customers regarding the Webex Services flaw?

Customers are required to implement the security updates released by Cisco to mitigate the vulnerabilities.

5

Who is the vendor addressing the Webex Services vulnerabilities?

Cisco is the vendor addressing the security vulnerabilities in their Webex Services platform.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203