# Cisco Webex Services Critical Improper Certificate Validation Flaw (CVE-2026-20184) Enables Man-in-the-Middle Against Cloud Meeting Traffic

> Cisco has disclosed CVE-2026-20137, a critical improper certificate validation vulnerability (CVSS 9.1) in the cloud-based Webex Services platform. The flaw allows an unauthenticated remote attacker in a network-privileged position to intercept, decrypt, or tamper with Webex meeting signaling and media traffic against Cisco's cloud endpoints. It is one of four critical vulnerabilities disclosed by Cisco on 2026-04-16 requiring customer-side action.

- **Published:** 2026-04-16T12:00:00Z
- **Last reviewed:** 2026-04-16T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0376
- **ID:** TL-2026-0376
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20137, CVE-2026-20138, CVE-2026-20139, CVE-2026-20140, CVE-2026-20184

## Description

On 2026-04-16 Cisco's Product Security Incident Response Team (PSIRT) released a batch of four critical security advisories affecting cloud-hosted Webex Services, Webex App clients, and on-premises integration components. The most severe of the batch, tracked as CVE-2026-20184, is an improper certificate validation vulnerability (CWE-295) in the TLS handshake logic of multiple Webex Services components responsible for brokering signaling between Webex App clients and the cloud meeting infrastructure.

The root cause is that specific subsystems within Webex Services failed to verify the full certificate chain, subject alternative name (SAN) binding, and revocation status of server certificates presented by peer components during service-to-service and client-to-service TLS setup. An attacker able to observe or redirect traffic between a Webex App client and webex.com / *.webex.com cloud endpoints — for example by controlling an upstream ISP, a rogue captive portal, a compromised VPN concentrator, or an attacker-controlled Wi-Fi access point — can present a forged or mis-issued certificate that the vulnerable component accepts without fully validating. Successful exploitation yields a man-in-the-middle position that enables the attacker to (1) decrypt meeting signaling and SIP/SDP exchanges, (2) harvest SSO bearer tokens and meeting join PINs relayed over the compromised channel, (3) inject modified control messages into active sessions, and (4) tamper with media negotiation to downgrade encryption parameters on secondary channels.

Cisco confirmed that no authentication or user interaction is required; the vulnerability is reachable pre-authentication in the public network path that every Webex client traverses to reach cloud tenants. Because the vulnerable logic resides primarily in Cisco's cloud-managed service mesh, Cisco has deployed a mitigating server-side fix that customers must pair with updated Webex App clients (versions 44.4.x and later) to obtain full protection. Earlier App clients continue to permit the weaker validation path until upgraded. The batch of four advisories collectively affects Webex Services, Webex App for Windows/macOS/Linux/iOS/Android, Webex Meetings virtual desktop plugins, and the Webex Hybrid Data Security node that bridges on-premises key material to the cloud.

While Cisco states it is not aware of public exploitation at disclosure time, the company observed attempted anomalous TLS negotiations against a small number of customer tenants during the preceding 60-day window, consistent with reconnaissance of the affected code path. Independent researchers at a European CERT replicated the attack end-to-end against lab Webex endpoints using a transparent proxy with a mis-signed wildcard, demonstrating full recovery of meeting join tokens and the ability to silently join otherwise-authenticated meetings as an invisible participant. The disclosure meaningfully elevates supply-chain MitM risk for enterprises, government tenants, and regulated industries that rely on Webex for privileged communications; operational telemetry suggests Webex cloud serves more than 95 million monthly active identities across more than 180 countries.

## MITRE ATT&CK

- T1595 Active Scanning
- T1590 Gather Victim Network Information
- T1588 Obtain Capabilities
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1557 Adversary-in-the-Middle
- T1557.002 ARP Cache Poisoning
- T1040 Network Sniffing
- T1539 Steal Web Session Cookie
- T1606 Forge Web Credentials
- T1185 Browser Session Hijacking
- T1573 Encrypted Channel
- T1102 Web Service
- T1684.001 Impersonation
- T1553 Subvert Trust Controls
- T1567 Exfiltration Over Web Service

## Sources

- [Cisco Security Advisory — Webex Services Certificate Validation Flaw (cisco-sa-webex-cert-val-2026-04)](https://sec.cloudapps.cisco.com/security/center/publicationListing.x)
- [CISA Alert — Cisco Webex Critical Vulnerabilities Require Customer Action](https://www.cisa.gov/news-events/alerts/)
- [NVD Entry — CVE-2026-20137](https://nvd.nist.gov/vuln/detail/CVE-2026-20137)
- [MITRE CWE-295 — Improper Certificate Validation](https://cwe.mitre.org/data/definitions/295.html)
- [European CERT Technical Write-up — Webex TLS Chain Validation Bypass PoC](https://cert.europa.eu/publications/threat-intelligence/)
- [Cisco Talos Blog — Detecting Anomalous TLS Negotiations Against Webex Tenants](https://blog.talosintelligence.com/)
- [MITRE ATT&CK T1557.003 — Adversary-in-the-Middle: ARP Cache Poisoning](https://attack.mitre.org/techniques/T1557/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0376
