The images in this article were generated with artificial intelligence. How we publish
Cisco has published corrections for four critical vulnerabilities that affect its Identity Services (ISE) services and Webex Services related functions. These failures potentially allow from remote code execution until an attacker passes through any user within the service, with consequences ranging from loss of integrity in a session to complete system control taking or generation of service denials.
The risk is high and concrete: one of the vulnerabilities (referred to as CVE-2026-20184) is related to the incorrect validation of certificates in the integration of SSO with Hub Control in Webex Services, which could allow an unauthenticated attacker to plant identities within the service. Three other (CVE-2026-20147, CVE-2026-20180 and CVE-2026-20186) are input validation errors in Cisco ISE and the Passive Identity Connector (ISE-PIC) component that, in different privilege scenarios, allow from remote code execution to the execution of commands in the underlying operating system and post-root elevation.

According to Cisco's safety notice, a successful exploitation of ISE vulnerabilities could even cause a node in single node deployments to stop being available, causing a state of denial of service in which equipment that has not previously authenticated could not access the network until the node is restored. Cisco points out that, for the moment, it has no indication of active exploitation of these failures, but strongly recommends that published updates be implemented as soon as possible. The official communiqué and recommendations of Cisco are available at its security centre: Cisco Security Advisories.
With regard to specific actions, vulnerability CVE-2026-20184 is managed from the cloud and does not require customers to apply a software patch; however, Cisco advises organizations using SSO to load a new SAML certificate from their identity provider (IDP) in Hub Control to mitigate the user supplanting vector. For problems affecting ISE and ISE-PIC, Cisco has released corrections in specific versions: CVE-2026-20147 is solved in versions such as ISE 3.1 (with 3.1 Patch 11), 3.2 (Patch 10), 3.3 (Patch 11), 3.4 (Patch 6) and 3.5 (Patch 3); vulnerabilities CVE-2026-20180 and CVE-2026-20186 are corrected in ISE 3.2 (Patch 8), 3.3 (Patch 8), 3.4 (Patch 4) and do not affect 3.5. If a version prior to those mentioned is used, Cisco recommends migrating to a corrected version as soon as possible. The product support page is available for download information and updates guides for ISE: Cisco Identity Services Engine - Support.
Beyond installing patches, it is appropriate to take complementary mitigation measures: to review records and telemetry in search of abnormal behaviors that match exploitation attempts, to restrict administrative access and to audit accounts with privileges, to make backup before applying updates and to test patches in pre-production environments where possible to avoid unexpected impacts. It is also recommended to renew the SAML certificates and validate the SSO configuration to minimize the risk of supplanting, taking as a reference good practices on SAML and identity control. Resources on good practice in identity management and entry validation are available from the NIST and the OWASP community: NVD (NIST) and OWASP - Validation of Entries.

From an operational perspective, security teams should prioritize the instances exposed to the Internet and the nodes in single node topology, as in these environments the operation could have an immediate operational impact on network access. If there are doubts as to whether an installation is affected, it is appropriate to consult Cisco's technical notices and, if necessary, open a case with support to obtain specific guidance on the temporary update or mitigation.
The usual dynamics in these scenarios are clear: even if there is no public evidence of exploitation at present, the failures with remote and supplanting capacity represent a risk window too wide to postpone the corrections. Update systems, validate SSO configurations and audit administrative accounts should be at the top of the task list of any safety or network management officer using Cisco ISE or Webex Services.
Finally, keeping the asset inventory up-to-date and establishing response processes that include detection, containment and recovery will help reduce the impact if an organization detects an attempt at intrusion. To keep up with public alerts and official CVE entries, you can also follow the NIST vulnerability database and Cisco PSIRT's own news on its security portal.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...