Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day | TechRadar

Four critical flaws were recently patched Discover insights about cisco tells webex users to patch critical security flaws immediately, as experts find its wi-f

TechnologyInnovationBest PracticesGuideTutorial
Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day | TechRadar
Listen to Article
0:00
0:00
0:00

Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Cisco patches four critical flaws in Webex Services, including SSO and Identity Services Engine RCE bugs

No exploitation reported before fixes; users must update SAML certificates in Control Hub

Separate IOS XE bug causes Wi‑Fi access points to bloat logs and fail updates, affecting 230+ models

Cisco has pushed a new patch to address four critical-severity vulnerabilities plaguing its cloud-based Webex Services platform - and has also warned Wi-Fi access points users of a bug in certain versions of IOS XE that could result in a device bootloop.

Webex Services is a platform for communication and collaboration, letting people hold video meetings, send messages, make calls, and share files, all from one place.

It was found vulnerable to four flaws: CVE-2026-20184 (9.8/10 - a vulnerability in the integration of single sign-on (SSO)), CVE-2026-20147 (9.9/10 - a remote code execution bug in Cisco ISE and Cisco ISE-PIC), CVE-2026-20180, and CVE-2026-20186 (9.9/10 arbitrary code execution flaws in Cisco Identity Services Engine).

Cisco warns of critical SD-WAN security flaw which has been open since 2023

Solar Winds Serv-U has some critical security flaws, so users should update now or face attack

HPE warns of dangerous security flaw which could allow Aruba OS password resets

Apparently, no threat actors found these flaws before they were patched: "Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token," Cisco said in its security advisory.

"A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services."

While Cisco patched the flaws, it also stressed that those using SSO integration should upload a new SAML certificate for their identity provider (Id P) to Control Hub.

At the same time, the company warned its access points users of a bug that could render their devices useless. In a separate advisory, Cisco said how “certain Cisco Access Points (APs) may fail to download new software images or Access Point Service Packs”, because an updated library in Cisco IOS XE generates a log file that grows by 5MB every day.

The file, which cannot be deleted from the command line interface, will keep growing until there is no more room on the disk, essentially preventing any further updates to be installed on the device.

Versions 17.12.4, 17.12.5, 17.12.6, and 17.12.6a are affected, it was said. In total, more than 230 different models are at risk, Cisco said.

“The longer an AP runs the affected software, the higher the probability that a software download will fail due to insufficient disk space,” the advisory reads..

Trend Micro warns of worrying security flaw allowing full Windows takeover, so patch now

Veeam says critical security flaws may be exposing backup servers to RCE attacks

Zyxel warns over a dozen routers could be affected by critical RCE security flaw

Users should, therefore, move to a version that doesn’t bloat the device, but it’s not as straightforward of a process. Cisco published a detailed guide, so if you’re using the company’s APs, make sure to read it here.

➡️ Read our full guide to the best antivirus

  1. Best overall: Bitdefender Total Security
  2. Best for families: Norton 360 with Life Lock
  3. Best for mobile: Mc Afee Mobile Security

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow Tech Radar on Tik Tok for news, reviews, unboxings in video form, and get regular updates from us on Whats App too.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

1 The Tor Project takes a major step toward launching its mobile VPN with successful Cure 53 audit

2 You might soon be able to buy luxury Gucci-branded Android XR smart glasses, and we dread to think what they’ll cost

3 Legendary strategy franchise Heroes of Might and Magic is back in the first new entry in over a decade — 'This is one of those generational games' developer says

47 new movies and TV shows to watch on Netflix, Prime Video, HBO Max, and more this weekend (April 17)

5 Tomodachi Life: Living the Dream devs say there was 'a big debate' about whether Miis should fart — 'We really obsessed over getting the sound just right'

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets

  • Start exploring exclusive deals, expert advice and more

  • Unlock and manage exclusive Techradar member rewards

  • Cisco tells Webex users to patch critical security flaws immediately, as experts find its Wi-Fi boxes may be filling their disks with undeletable data every day

  • When you purchase through links on our site, we may earn an affiliate commission

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.