Cisco patches critical flaws in Identity Services Engine and Webex
Cisco has released fixes for several serious vulnerabilities in Identity Services Engine (ISE) and Webex. Three of them, CVE-2026-20147, CVE-2026-20180 and CVE-2026-20186, carry a CVSS score of 9.9 and stem from inadequate validation of user input. An authenticated user can send specially crafted HTTP requests and run arbitrary commands on the underlying operating system, including as root. Exploitation requires valid administrative credentials, at minimum with read-only rights. In Webex, CVE-2026-20184 with a CVSS score of 9.8 could allow an unauthenticated attacker to impersonate any user, caused by improper certificate validation in the SSO integration with Cisco Control Hub. Cisco has already remediated the Webex issue in the cloud service and knows of no misuse.
What this means for your organisation
ISE is often the gateway into the network and decides who reaches what. If it falls, access control falls with it. Requiring a read-only login raises the bar, but many organisations have more read accounts than they realise, and they are frequently used by integrations and managed service providers. The Webex flaw is worth noting even though it is fixed: it shows how much trust rests on a single SSO integration.
Berigo recommends
- Upgrade ISE instances now. There is no workaround.
- Review who genuinely holds administrative access to ISE, read-only included, and remove dormant accounts.
- Require your managed service providers to confirm in writing that their ISE instances are patched.
- Map which services depend on the same SSO integration, so you know the blast radius next time.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch