Cisco patches critical Webex SSO and ISE vulnerabilities (CVE-2026-20184, -20147, -20180, -20186)

Cisco released patches addressing 15 vulnerabilities, including a critical improper certificate validation in Webex SSO (CVE-2026-20184) that could let unauthenticated attackers impersonate any user via Control Hub. Three critical flaws in Identity Services Engine (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186) allow authenticated attackers — including those with read-only admin rights — to execute arbitrary commands on the underlying OS and potentially escalate to root. Cisco advises applying patches and, for Webex SSO customers, uploading a new IdP SAML certificate to Control Hub.

Part of the PlainSec briefing for 2026-04-16

Sources