Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2379 articles · 111906 vulns · 38/41 feeds (7d)
← Back to list
9.8
CVE-2026-20184PATCHED
cis · webex services

Cisco Webex Meetings Certificate Validation Vulnerability

Description

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.

Affected Products

VendorProductVersions
ciswebex services39.7.7, 39.9, 40.4.10, 39.6, 40.6.2, 39.8.2, 39.8.4, 40.1, 39.11, 39.7.4, 39.9.1, 40.4, 40.6, 39.7, 39.8, 39.8.3, 40.2, 39.10, 42.6, 42.7, 42.8, 42.9, 42.10, 42.11, 42.12, 43.1, 43.2, 43.3, 43.4, 43.4.1, 43.4.2, 43.5.0, 43.6.0, 43.6.1, 43.7, 43.8, 43.9, 43.10, 43.11, 43.12, 44.1, 44.2, 44.3, 44.4, 44.5, 44.6, 44.7, 44.8, 44.9, 44.10, 44.11, 44.12, 45.1, 45.2, 45.3, 45.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciswebexcert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL

Related News (10 articles)

Tier D
The Hacker News4h ago
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
→ No new info (linked only)
Tier D
CSO Online3d ago
Cisco Systems issues three advisories for critical vulnerabilities in Webex, ISE
→ No new info (linked only)
Tier D
BleepingComputer4d ago
Cisco says critical Webex Services flaw requires customer action
→ No new info (linked only)
Tier D
The Hacker News4d ago
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
→ No new info (linked only)
Tier B
BSI Advisories4d ago
[NEU] [hoch] Cisco WebEx: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek4d ago
Cisco Patches Critical Vulnerabilities in Webex, ISE
→ No new info (linked only)
Tier D
Heise Security4d ago
Cisco: Kritische Codeschmuggel-Lücken in ISE und mehr geschlossen
→ No new info (linked only)
Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits Cisco (16 avril 2026)
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-20184 | Cisco Webex Meetings up to 45.4 certificate validation (cisco-sa-webex-cui-cert-8jSZYhWL)
→ No new info (linked only)
Tier A
Cisco Security5d ago
Cisco Webex Services Certificate Validation Vulnerability
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
45.4
CWECWE-295
PublishedApr 15, 2026
Last enriched3d agov3
Tags
CVE-2026-20184
Trending Score80
Source articles10
Independent9
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20147EXP
Cisco Identity Services Engine Remote Code Execution Vulnerability
Trending: 86
CRITICALCVE-2026-20180
Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
Trending: 64
CRITICALCVE-2026-20186
Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
Trending: 64
MEDIUMCVE-2026-20148EXP
Cisco Identity Services Engine Path Traversal Vulnerability
Trending: 34
MEDIUMCVE-2026-20132EXP
Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
Trending: 32

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 15, 2026
Discovered by ZDM
Apr 15, 2026
Updated: patchAvailable
Apr 15, 2026
Patch Available
Apr 16, 2026
Updated: tags
Apr 16, 2026

Version History

v3
Last enriched 3d ago
v3Tier D3d ago

Updated description with detailed steps for patching and confirmed CVSS score of 9.8, marked as actively exploited.

tags
via CSO Online
v2Tier C5d ago

Updated actively exploited status to true and added patch available version 45.4.

patchAvailable
via VulDB
v15d ago

Initial creation