Cisco Webex & ISE Critical CVEs
Cloud Security Alliance (CSA)
pdf
2026-04-17T00:00:00
Abstract
This research details four critical vulnerabilities affecting Cisco Webex and Cisco Identity Services Engine (ISE). CVE-2026-20184 in Webex enables unauthenticated user impersonation via a SAML certificate validation flaw, requiring manual administrator intervention to remediate. Simultaneously, three critical vulnerabilities in Cisco ISE (CVE-2026-20147, CVE-2026-20180, and CVE-2026-20186) allow authenticated attackers—including those with only read-only administrative access—to achieve remote code execution (RCE) and escalate privileges to root.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)