• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cisco patches four critical identity services, webex flaws enabling code

Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution

You are here: Home / General Cyber Security News / Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
April 16, 2026

Cisco has announced patches to address four critical security flaws impacting Identity Services and Webex Services that could result in arbitrary code execution and allow an attacker to impersonate any user within the service.

The details of the vulnerabilities are below –

  • CVE-2026-20184 (CVSS score: 9.8) – An improper certificate validation in the integration of single sign-on (SSO) with Control Hub in Webex Services that could allow an unauthenticated, remote attacker to impersonate any user within the service and gain unauthorized access to legitimate Cisco Webex services.
  • CVE-2026-20147 (CVSS score: 9.9) – An insufficient validation of user-supplied input vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow an authenticated, remote attacker in possession of valid administrative credentials to achieve remote code execution by sending crafted HTTP requests.
  • CVE-2026-20180 and CVE-2026-20186 (CVSS scores: 9.9) – Multiple insufficient validation of user-supplied input vulnerabilities in ISE could allow an authenticated, remote attacker in possession of read only admin credentials to execute arbitrary commands on the underlying operating system of an affected device by sending crafted HTTP requests.

“A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root,” Cisco said in an advisory for CVE-2026-20147, CVE-2026-20180, and CVE-2026-20186.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“In single-node ISE deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.”

CVE-2026-20184 requires no customer action as it’s cloud-based. However, customers who are using SSO are advised to upload a new identity provider (IdP) SAML certificate to Control Hub. The remaining vulnerabilities have been addressed in the following versions –

  • CVE-2026-20147
    • Cisco ISE or ISE-PIC Release earlier than 3.1 (Migrate to a fixed release)
    • Cisco ISE Release 3.1 (3.1 Patch 11)
    • Cisco ISE Release 3.2 (3.2 Patch 10)
    • Cisco ISE Release 3.3 (3.3 Patch 11)
    • Cisco ISE Release 3.4 (3.4 Patch 6)
    • Cisco ISE Release 3.5 (3.5 Patch 3)
  • CVE-2026-20180 and CVE-2026-20186
    • Cisco ISE Release earlier than 3.2 (Migrate to a fixed release)
    • Cisco ISE Release 3.2 (3.2 Patch 8)
    • Cisco ISE Release 3.3 (3.3 Patch 8)
    • Cisco ISE Release 3.4 (3.4 Patch 4)
    • Cisco ISE Release 3.5 (Not Vulnerable)

While Cisco noted that it is not aware of any of these shortcomings being exploited in the wild, it’s essential that users update their instances to the latest version for optimal protection.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «obsidian plugin abuse delivers phantompulse rat in targeted finance, crypto Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
  • Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
  • Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to Temu
  • UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
  • n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
  • Critical nginx-ui Vulnerability CVE-2026-33032 Allows Unauthenticated Nginx Takeover
  • April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
  • Deterministic + Agentic AI: The Architecture Exposure Validation Requires
  • Microsoft Issues Patches for SharePoint Zero-Day and 168 Other Vulnerabilities
  • OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams

Copyright © TheCyberSecurity.News, All Rights Reserved.