CVE-2026-20184Patch

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 28 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 16 signals
  • Technical details provided in 23 signals
  • Disclosure: 12 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 18 mentions (2026-04-16); latest day: 1
  • 28 total mentions across 7 days

Deep dive

Activity timeline28 mentions / 7d
0591418Mentions · 2026-04-15: 1Mentions · 2026-04-16: 18Mentions · 2026-04-17: 5Mentions · 2026-04-20: 1Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-05-01: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-16: 13Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 15Technical Details · 2026-04-17: 4Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 1Technical Details · 2026-05-01: 104-1504-1604-1704-2004-2304-2405-01
Signal classification3 categories
Patch
1346.4%
Disclosure
1242.9%
General
310.7%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-1618
Disclosure6General2Patch10
2026-04-175
Disclosure2General1Patch2
2026-04-201
Disclosure1
2026-04-231
Disclosure1
2026-04-241
Patch1
2026-05-011
Disclosure1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    Cisco Webex CVE-2026-20184 allows unauthenticated user impersonation via SSO flaw. Fix requires a manual certificate update in Control Hub. Act now! #WebexSecurity #SSO #Cisco #InfoSec #CyberSecurity #CVE202620184 #SAML #IdentityAccess https://securityonline.info/cisco-webex-sso-vulnerability-cve-2026-20184-impersonation-fix/ https://t.co/Ibv1vll4sz

    Post summary

    The post highlights the Cisco Webex SSO flaw that allows unauthenticated impersonation, and advises a manual certificate update in Control Hub to remediate it.

    0601421.1K
    12.3K followersView on X
  • yousukezan@yousukezan
    Patch

    Cisco Webex ServicesとCisco Control HubのSSO連携において、証明書の不適切な検証があり、未認証の遠隔攻撃者が細工したトークンを送り込むと、関連する証明書の正当性確認が不十分なため、任意の利用者として受け入れられるおそれがあった。CVE-2026-20184として追跡されている。 悪用されれば、経営会議への侵入、保存文書や録画、チャット記録の閲覧、さらに信頼済みアカウントを足場にした横展開にもつながり得る。Ciscoはクラウド基盤側で修正を実施済みだが、利用組織にはControl Hubで新しいIDP用SAML証明書をアップロードし、SSO設定を確認する対応が求められる。現時点でCisco PSIRTは、公開された悪用や実際の不正利用は把握していないとしている。 https://securityonline.info/cisco-webex-sso-vulnerability-cve-2026-20184-impersonation-fix/

    Post summary

    The CVE-2026-20184 flaw in Cisco Webex and Control Hub allows forged SSO tokens to impersonate users; Cisco has patched the cloud side and recommends uploading a new SAML certificate, with no known exploitation reported.

    010541.4K
    14.3K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🏢 أنظمة Enterprise: ⚙️ نظام Cisco ISE: التقييم: 9.9 | (CVE-2026-20147, 20180, 20186) ⚠️ تسمح للمستخدم الإداري بتنفيذ أوامر عن بُعد (RCE) وترقية الصلاحيات إلى Root. 📊 نظام SAP Business Planning: التقييم: 9.9 | (CVE-2026-27681) ⚠️ هجوم (SQL Injection) في ABAP يتيح التحكم بقواعد البيانات . 🔑 نظام Cisco Webex SSO: التقييم: 9.8 | (CVE-2026-20184) ⚠️ تخطي المصادقة الموحدة.

    Post summary

    The post lists newly disclosed high‑severity CVEs affecting Cisco and SAP systems, detailing RCE, privilege escalation, SQL injection, and authentication bypass, but offers no evidence of exploitation or remediation.

    100421.8K
    49.3K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    うわーいっぱいでてるるるるる Cisco Security Advisories https://sec.cloudapps.cisco.com/security/center/publicationListing.x CVE-2026-20184 Cisco Webex Services Certificate Validation Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL CVE-2026-20147 CVE-2026-20148 Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ CVE-2026-20180 CVE-2026-20186 Cisco Identity Services Engine Remote Code Execution Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv 【セキュリティ ニュース】「Cisco ISE」に複数の深刻な脆弱性 - 一部修正パッチを準備中(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/183510

    Post summary

    The tweet lists newly disclosed Cisco vulnerabilities with advisory links and notes that patches are being prepared, but no PoC, exploit code, or active exploitation details are provided.

    000421.3K
    11.7K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Cisco Webex ServicesのControl Hubに重大(Critical)な脆弱性。CVE-2026-20184はCVSSスコア9.8で、SSOでの不適切な証明書検証に起因し、無認証の攻撃者が任意のなりすましを行うことができた。利用者側でのIdP SAML再アッブロード要。実際の悪用は未確認。 https://securityonline.info/cisco-webex-sso-vulnerability-cve-2026-20184-impersonation-fix/

    Post summary

    The post announces a critical vulnerability (CVE-2026-20184) in Cisco Webex Control Hub, detailing how improper SSO certificate validation allows unauthenticated impersonation but notes that real-world exploitation has not been confirmed and hints at a workaround.

    01030933
    7.6K followersView on X
  • INSA- የኢንፎርሜሽን መረብ ደህንነት አስተዳደር@INSAEthio
    Patch

    Cisco fixes critical #Webex flaw (CVE-2026-20184) that could allow user impersonation via SSO. ⚠️ Action required: Organizations must update SAML certificates to avoid disruption. No active attacks reported—but timely patching is critical. #INSA #DigitalEthiopia2030 https://t.co/C1Dw2V4Px4

    Post summary

    The tweet announces Cisco’s patch for Webex CVE‑2026‑20184, urging SAML certificate updates; no active exploitation has been reported.

    01011160
    1.8K followersView on X
  • RedLegg@RedLegg
    Patch

    Security Bulletin: Cisco Webex (CVE-2026-20184, CVSS 9.8) allows auth bypass and user impersonation via SSO flaw. Update configs and certs now. #ThreatIntel #RedLeggCTI https://hubs.li/Q04crJQs0

    Post summary

    Cisco Webex CVE‑2026‑20184 enables authentication bypass and user impersonation via an SSO flaw; administrators should promptly update configurations and certificates.

    0101074
    2.2K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical #CiscoWebex vulnerability (CVE-2026-20184) allows remote attackers to impersonate users. Organizations must update SAML certificates in Webex Control Hub immediately. Link: https://thedailytechfeed.com/critical-cisco-webex-flaw-allows-remote-user-impersonation-immediate-saml-update-required/ #Security #Vulnerability #Update #Webex #CVE #Impersonation #Remote #Attackers #Organizations #Certificates #Control #Hub #Tech #Threat #Protection #Software #Network #Safety #Alert #Patch

    Post summary

    The post alerts about a critical Cisco Webex vulnerability (CVE-2026-20184) that allows remote user impersonation and urges immediate SAML certificate updates.

    0100019
    279 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    🚨 Cisco Webex & ISE Critical Vulnerabilities (CVE-2026-20184, CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) SSO auth bypass + input validation flaws → user impersonation + remote code execution 💡 Lesson: Identity systems are high-value targets — one flaw = full system compromise ⚠️ Action: Update Cisco ISE immediately + rotate SSO certificates, don’t delay patching critical auth systems https://thehackernews.com/2026/04/cisco-patches-four-critical-identity.html

    Post summary

    The post announces four critical Cisco Webex & ISE CVEs involving SSO bypass and RCE, emphasizes the high risk to identity systems, and urges immediate patching and certificate rotation.

    01000193
    6.2K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-20184: Cisco Webex SSO Certificate Validation Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04f7fW00

    Post summary

    The text announces CVE-2026-20184, a Cisco Webex SSO certificate validation bypass, and offers guidance on how businesses should respond.

    0000071
    29 followersView on X
  • TheCybersecurity.club@TheCyberse46292
    Patch

    Cisco just patched 4 critical flaws in Webex & Identity Services. One (CVE-2026-20184, 9.8) lets attackers impersonate ANY user via SSO bypass. That means silent access to calls, chats, and data. Update NOW before it’s exploited. #CyberSecurity #Cisco #Infosec

    Post summary

    Cisco has released patches for four critical Webex and Identity Services flaws, including CVE‑2026‑20184, a high‑severity SSO bypass that allows user impersonation; users are urged to update immediately.

    0000089
    3 followersView on X
  • UWillC@uwillc
    Disclosure

    CVE-2026-20147/180/186 (ISE, 9.9, Apr 15): read-only admin = root. CVE-2026-20184 (Webex, 9.8): SSO auth bypass. CVE-2026-20127 (SD-WAN, 10.0): Talos traces exploitation to 2023. March-September bundle model is dead.

    Post summary

    The text lists a set of newly disclosed CVEs with brief technical descriptors, notes that CVE‑2026‑20127 was exploited in 2023, and mentions that the March‑September bundle model is no longer in use.

    0000054
    504 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20186 ❗ CVE-2026-20184 ❗ CVE-2026-20147 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-14/ https://t.co/43iRTTwbX3

    Post summary

    The tweet announces three Cisco product vulnerabilities (CVE‑2026‑20186, CVE‑2026‑20184, CVE‑2026‑20147) and points readers to a CERT.gov.py page for further details.

    00000122
    6.7K followersView on X
  • sajberinfo.com@SajberInfoBlog
    General

    Cisco Webex ranjivost (CVE-2026-20184) https://sajberinfo.com/2026/04/17/cisco-webex-ranjivost/ #certificatevalidation #ciscowebexranjivost #cloudvulnerability #criticalexploit #cybersigurnost #digitalnicertifikati #identityprotection #sigurnostkomunikacija #ssobezbjednost #webexnapad #webexsecurity

    Post summary

    The entry merely announces a new CVE with a reference link, lacking specific technical or operational details.

    0000055
    10 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical user impersonation in #CISCO #Webex CVE-2026-20184 CVSS: 9.8. An improper certificate validation in the SSO of the Control Hub can be exploited to compromise user accounts & gain access to sensitive info. https://ccb.belgium.be/advisories/warning-critical-improper-certificate-validation-cisco-webex-can-lead-user-impersonation #Patch #Patch #Patch

    Post summary

    The advisory announces a critical CVE‑2026‑20184 affecting Cisco Webex SSO certificate validation with a CVSS 9.8 score, but provides no exploit or patch details.

    00000202
    7.2K followersView on X
  • securityrss.ai@securityRSS
    Patch

    Cisco has released patches for four critical vulnerabilities in Identity Services and Webex Services that could lead to arbitrary code execution and user impersonation. Key vulnerabilities include CVE-2026-20184 (CVSS 9. https://thehackernews.com/2026/04/cisco-patches-four-critical-identity.html

    Post summary

    Cisco issued patches for four critical Identity Services and Webex Service vulnerabilities that could lead to arbitrary code execution and user impersonation.

    0000068
    86 followersView on X
  • Cyber Daily News@CyberDaily_News
    Patch

    Cisco patched 4 criticals: Webex SSO cert validation (CVE-2026-20184, CVSS 9.8) allows unauth user impersonation; three ISE bugs (CVSS 9.9) enable RCE, one reachable via read-only admin. No ITW reports yet. https://securityaffairs.com/190909/security/cisco-fixed-four-critical-flaws-in-identity-services-and-webex.html #infosec #Cisco #Webex #ISE

    Post summary

    Cisco has patched four critical vulnerabilities affecting Webex SSO and ISE, but no evidence of live exploitation has been reported.

    0000059
    20 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    Critical Cisco Webex CVE-2026-20184 Enables Remote User Impersonation https://thecybrdef.com/cisco-webex-cve-2026-20184-user-impersonation-vulnerability/

    Post summary

    The headline announces a critical vulnerability (CVE‑2026‑20184) in Cisco Webex that permits remote user impersonation, with no evidence of PoC, exploit code, or active attacks, and no patch details are provided.

    0000042
    3 followersView on X
  • SempreUpdate@SempreUpdate
    Patch

    Cisco Webex tem vulnerabilidade crítica (CVE-2026-20184); veja como corrigir https://sempreupdate.com.br/cisco-webex-vulnerabilidade-critica-cve-2026-20184-correcao/

    Post summary

    The article announces a critical vulnerability in Cisco Webex (CVE-2026-20184) and provides guidance on how to apply the fix.

    0000058
    4.7K followersView on X
  • thibault@akril
    General

    [IT-Connect] - Cisco Webex – CVE-2026-20184 : cette faille critique nécessite une action de l’admin - https://www.it-connect.fr/cisco-webex-cve-2026-20184-cette-faille-critique-necessite-une-action-de-ladmin/ 👌😁

    Post summary

    The article signals a critical Cisco Webex vulnerability (CVE-2026-20184) requiring admin action, but provides no details on PoC, exploit, patch, technical specifics, or active exploitation.

    0000041
    680 followersView on X

Explore more