INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco Fixes Identity Services and Webex Flaws

| 2026-04-16 19:19 CRITICAL HIGH
Executive Summary AI-generated
The recent incident data reveals a critical flaw in Cisco's Identity Services and Webex, allowing attackers to execute arbitrary code and impersonate any user within the affected services. The vulnerabilities were identified as four critical flaws in Identity Services Engine (ISE) and ISE-PIC, which could be exploited remotely via crafted HTTP requests. These exploits have been patched by Cisco, but customers are advised to upload a new SAML certificate for their identity provider (IdP) to Control Hub to avoid service interruption. The company has also warned that no evidence of exploitation was found in attacks, indicating the potential severity of this vulnerability.
Technical Mitigations AI-generated
* Implement secure authentication and authorization: Ensure that all users have strong, unique passwords and that access to sensitive data is restricted to necessary personnel. Implement multi-factor authentication (MFA) whenever possible. * Keep operating systems and software up-to-date: Regularly update operating systems, browsers, and other software to ensure that known vulnerabilities are patched before they can be exploited by attackers. * Use secure protocols for communication: Use HTTPS or SFTP instead of HTTP when transferring sensitive data over the internet. This will help prevent eavesdropping and tampering with data in transit. * Monitor system logs and perform regular security audits: Regularly review system logs to detect potential security incidents, such as unauthorized access attempts or suspicious activity. Perform regular security audits to identify vulnerabilities and weaknesses in systems and applications. * Implement a secure patch management process: Develop a plan for applying patches to all affected systems and software, including testing and verification of the effectiveness of each patch before deploying it to production environments.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20184CVE-2026-20184 CVE-2026-20186CVE-2026-20186 CVE-2026-20180CVE-2026-20180 CVE-2026-20147CVE-2026-20147 CVE-2026-20131CVE-2026-20131
Target & Sectors
Global Scope
Incident Timeline
‎late January 2026
Threat actors exploited a zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC) to target Interlock ransomware attacks.
tactic Ransomware
vulnerability CVE-2026-20131
attribution Secure Firewall Management Center
‎2026/03/17
Threat actors exploited a maximum-severity vulnerability in Cisco's Secure Firewall Management Center (FMC) to target Interlock ransomware attacks.
tactic Ransomware
vulnerability CVE-2026-20131
attribution Secure Firewall Management Center
‎Apr 16, 2026
Threat actors exploited four critical vulnerabilities in Cisco's Identity Services and Webex to gain unauthorized access.
‎2026/04/16
Cisco fixed four critical flaws in Identity Services and Webex.
organisation Identity Services
organisation Control Hub
organisation Vulnerability / Network Security
organisation Identity Services and Webex Services
organisation Cisco Webex
organisation Control Hub in Webex Services
organisation IdP
organisation SSO
organisation CVE-2026-20147
organisation Identity Services Engine
organisation ISE-PIC
organisation the Identity Services Engine
organisation Cisco
infrastructure 3.1
organisation Cisco ISE
organisation ISE-PIC Release
organisation Migrate
organisation CVE-2026
organisation Passive Identity Connector
organisation CVSS
infrastructure 3.2
infrastructure 3.4
infrastructure 3.5
organisation Identity Services and Webex
organisation SecurityAffairs
organisation Webex Services
organisation Product Security Incident Response Team
infrastructure 3.3
organisation Cisco ISE Release
organisation DoS
‎May 12
Threat actors used a vulnerability in Cisco's Identity Services and Webex to target the Autonomous Validation Summit on May 12.
organisation the Autonomous Validation Summit
general_metric 14 May
Tactical Metrics
Metrics
infrastructure
‎3.1
Software Version
Metrics
infrastructure
‎3.2
Software Version
Metrics
infrastructure
‎3.3
Software Version
Metrics
infrastructure
‎3.4
Software Version
Metrics
infrastructure
‎3.5
Software Version
Intelligence Sources