Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Cisco patched the Webex cloud service for critical vulnerability CVE-2026-20184, but that alone did not complete remediation for every customer. Organizations using trust anchors in Webex’s SAML single sign-on (SSO) configuration needed to upload a replacement identity-provider (IdP) certificate or updated IdP metadata in Control Hub. Cisco’s May 22, 2026 deadline has passed; administrators should check their configuration now and use Webex’s recovery process if SSO is already blocking access.

What CVE-2026-20184 could allow

Cisco disclosed CVE-2026-20184 on April 15, 2026, and updated its advisory the following day. Cisco rated it CVSS 9.8 and classified the cause as CWE-295, improper certificate validation. The flaw was in certificate validation in the integration between Cisco Webex Services and SAML SSO configured through Control Hub—not in the Webex desktop app, Meetings client, or a customer-owned Webex server.

According to Cisco’s security advisory, an unauthenticated remote attacker could potentially impersonate a Webex user by submitting a crafted token to a service endpoint. That describes a possible attack, not evidence that an attack occurred. Cisco said it was unaware of malicious exploitation when it published the advisory. The NIST NVD record lists the CVE and Cisco-provided details; Cisco is the source for the severity and technical claims here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which organizations needed to act?

The issue did not affect every Webex customer. The affected configuration was cloud-based Webex managed in Control Hub, using SAML SSO with trust anchors. Customers without SSO, or whose SSO configuration did not use the affected trust-anchor mechanism, were not necessarily affected. Cisco directs administrators to inspect their organization’s SSO setup in Control Hub to determine whether trust anchors are in use.

#1 Best Overall
Cisco 561 Headset - Mono - Black - Wireless - DECT 6.0-300 ft48 kHz - Over-The-Head - Monaural - Supra-aural - Uni-Directional, Electret, Condenser Microphone
  • Connectivity Technology: Wireless
  • Wireless Technology: DECT 6. 0
  • Wireless Operating Distance: 300 ft
  • Sound Mode: Mono
  • Maximum Frequency Response: 48 kHz

This was more than a routine certificate-expiration notice. The security flaw was in certificate validation, and Cisco said there was no workaround that remediated it. Cisco patched its cloud service, but customers with the affected configuration still had to update their SSO trust material.

Why the manual update was still necessary

Cisco could repair the Webex service code, but the customer’s SSO configuration still had to contain the correct IdP trust information. The required customer action was a configuration update, not a Webex software download or endpoint patch.

Cisco’s advisory describes uploading a new IdP SAML certificate. The operational instructions in the Webex Help Center describe uploading updated IdP metadata, which commonly includes the signing certificate. Follow the format required by your IdP and the Control Hub workflow; a certificate file and a metadata file are related but are not automatically interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
MKJ Cisco Phone Headset Corded RJ9 Telephone Headset Noise Canceling Mic
  • Crystal Clear Chat: Specially designed RJ9 phone headset work for Cisco phones providing high-definition and crystal-clear communication, and noise cancelling microphone blocks out unwanted background noise and pick up loud and clear sound which makes you feel that you are having a face to face conversation. What's more, single earpiece headset can be worn on either side and you can still communicate with your colleague while wearing it
  • Productivity and Extended Comfort: Call center telephone headset with microphone allows you to work efficiently and comfortably. You can concentrate on the conversation while working on the computer during conference calls. With MKJ phone headset for Cisco phone, you don't need to cradle the phone handset between the head and shoulder which caused pain in the neck. Adjustable headband will fit all sizes head and the soft ear cushion ensures added comfort even for long-time wearing
  • Great Durability: High-end materials and durable design ensure the wired headphones with microphone withstand the constant demands of all-day use in busy environments. The built-in reinforced cord will protect the headset against office chair wheels, and sharp objects on daily use. Stainless steel headband, superior quality speaker and noise cancelling microphone, and reliable plastic parts make this headset durable enough even for busy environment
  • Hearing Protection: MKJ telephone headset for Cisco phones corded RJ9 with built-in hearing protection circuit will provide users with safe and comfortable audio experience. It protects you from long term daily sudden sound burst, any sound above 118db is filtered out. It is suitable for those who takes a large volume of call every day, including call center agent, customer service, telemarketing workers etc
  • RJ9 Headset Compatibility: This noise-canceling Cisco headphones for work allow you to deal with other tasks during calls, and it works with most Cisco phones with RJ9 headset port, such as 6921, 6941, 6945, 6961, 7821, 7841, 7861, 7931G, 7940, 7940G, 7941, 7941G, 7942G, 7945, 7945G, 7960, 7960G, 7961, 7961G, 7962G, 7965G, 7970, 7970G, 7971G, 7975G, 7985G, 8811, 8841, 8845, 8851, 8861, 8865 and 8900, 8941, 8945, 8961, 9951, 9971

Check and update the SSO configuration

  1. Check status in Control Hub. Sign in and go to Management > Security > Authentication, then open the Identity provider tab. Review the IdP certificate status and expiry date. Check the Alerts center for Webex SSO certificate notices.
  2. Get fresh metadata from your IdP. Export the current SAML metadata from your identity provider’s management console. The exact process depends on the IdP and its rollover setup. Do not rely on an old downloaded file; make sure the metadata reflects the signing certificate the IdP is using.
  3. Upload the metadata. In Control Hub, return to Management > Security > Authentication > Identity provider, select the relevant IdP, and choose the upload control and Upload IdP metadata. Select the appropriate signing option: Less secure for self-signed metadata, or More secure for metadata signed by a public certificate authority.
  4. Run the SSO test. Choose Test SSO setup. In the new browser tab, authenticate through the IdP and confirm that the test completes successfully before closing the workflow.

If Control Hub shows certificate usage as “None,” Cisco’s Help Center still recommends proceeding with the upgrade because the certificate may be needed for future configuration changes. Follow the current Control Hub prompts and Cisco’s instructions for your organization rather than assuming that “None” means no action is needed.

If the May 22 deadline was missed

Cisco’s Help Center said it would remove the SSO trust anchors on May 22, 2026, and warned that users who had not uploaded the replacement certificate could lose the ability to sign in. That date has passed. Check the present certificate and trust-anchor status rather than assuming either that the update was completed automatically or that every account is already locked out.

If you can still access Control Hub, use the update steps above, then test fresh sign-ins. If broken SSO prevents administrators from reaching the normal Control Hub workflow, use Cisco’s documented SSO self-recovery process. It can provide a way to update the IdP metadata or temporarily disable SSO to regain administrative access.

Rank #3
Cisco Headset 562, Wireless Dual On-Ear DECT Headset with Multi-Source Base for US & Canada, Charcoal, 1-Year Limited Liability Warranty (CP-HS-WL-562-M-US=) (Renewed)
  • ENHANCED MOBILITY WIRELESS & SECURITY: The Headset 562 (dual ear cups) DECT technology provides users the freedom to roam up to 300 ft from the multi-source base (connects up to 3 devices) with secure crystal-clear audio and up to 9 hours of talk time
  • PREMIUM AUDIO, NOISE ISOLATION & CONTROL: Our comfortable, all-day wear design creates a full and rich sound that makes collaboration easier and music more enjoyable. On-ear controls allow access to key call control capabilities, mute/unmute, and volume
  • COMPATIBILITY: Cisco DECT headsets are optimized for Cisco Jabber/Webex devices/computers with USB-A ports. Also, compatible with Cisco IP Phones with USB-A, Bluetooth and/or RJ-9/AUX ports including 6851/6871/6900/7800/8800 models
  • INTEGRATED SERVICEABILITY: Easier to deploy, manage, and service when using Cisco headsets with Cisco Unified Communications Manager, Cisco Webex Control Hub, and Cisco devices

Temporarily disabling SSO is an access-recovery measure, not a fix for CVE-2026-20184. It changes the organization’s sign-in arrangement to cloud-managed passwords. Reconfigure SSO with the correct IdP certificate or metadata afterward. If recovery is unavailable or you cannot safely complete the change, Cisco directs customers to contact Cisco TAC or their contracted maintenance provider; a Cisco partner with access to the organization may also be able to help.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan the change around your IdP’s certificate rollover

If your IdP supports overlapping or multiple active signing certificates, its rollover process may let you stage the replacement and test it before retiring the old certificate. Verify the IdP’s own procedure; do not assume that every provider or configuration handles overlap the same way.

Cisco advises scheduling a maintenance window when the IdP supports only one certificate. New sign-ins may briefly fail during the change, even if existing sessions continue to work. Existing sessions are not a reliable test: the important check is whether a fresh SAML sign-in succeeds. Cisco estimates about 30 minutes for the change and post-change validation, but actual timing depends on the organization and IdP.

Rank #4
Cisco Headset 722, Wireless Dual On-Ear Bluetooth Headset with Webex Button, USB-A HD Bluetooth Adapter, Soft Case, Carbon Black, 2-Year Limited Liability Warranty (HS-WL-722-BUNA-C)
  • HYBRID WORK: Flip to mute mic boom, 23+ hours of talk time, one-button to join, AI voice-activated microphones to minimize background noise. On-ear controls, including a dedicated Webex button, allow quick access to call functions and media capabilities
  • PREMIUM AUDIO & DESIGN: Stay comfortable with the lightweight dual ear cup design that provides passive noise supression, clear audio, and all-day comfort. Keep background noise out of your calls and meetings with voice-activated microphones
  • COMPATIBILITY: Quick wireless pairing with Bluetooth capable devices. It also includes a USB-A HD Adapter, USB-A cables for versatile connection options. For business use, the Cisco Headset 720 Series is optimized for Webex and select Cisco devices
  • SECURITY & MANAGEMENT: Industry-leading hardware and software ensure communications stay secure. Easy to deploy, manage, and service
  • PEACE OF MIND: Two Year Limited Liability Warranty

Validate the change with fresh sign-ins

After uploading the metadata, test more than the administrator’s current browser session:

  • Open a fresh browser session and sign in to Webex.
  • Test Webex App sign-in as well as browser sign-in.
  • Verify both an administrator account and an ordinary employee account.
  • Check Webex services managed through Control Hub, including Meetings and Calling where used, and Cisco Jabber if it is integrated with the same SSO.
  • Review IdP sign-in logs for failed assertions, certificate mismatches, issuer or audience errors, and other federation errors.

If the Control Hub test fails, confirm that you uploaded IdP metadata—not service-provider metadata—from the correct tenant or environment. Check that the metadata is current, that its signing certificate matches the one active at the IdP, and that the correct self-signed or public-CA option was selected. Also check that changes were made on both sides: updating the IdP alone does not update Control Hub, and updating Control Hub alone does not change which certificate the IdP uses. If testing with a browser that already has a valid session, sign out or use a private window so an existing session is not mistaken for a successful new authentication.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Webex says certificate-expiry alerts are issued every 15 days starting 60 days before expiry—at 60, 45, 30, and 15 days. Treat alerts as a reminder to plan and validate certificate changes, not as a substitute for checking the trust-anchor status associated with this incident.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.