logo

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

ID: 22be0a50-51e6-53d0-9502-e662f82d25a3

STIX ID: report--22be0a50-51e6-53d0-9502-e662f82d25a3

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-01-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cisco released a patch for a critical 9.9-rated privilege escalation vulnerability (CVE-2025-20156) in Cisco Meeting Management caused by improper REST API authorization; an authenticated low-privilege attacker could gain admin access to edge nodes. Most releases are affected with no workaround available—users should upgrade (3.9→3.9.1, migrate 3.8 and earlier; 3.10 unaffected); Cisco has not observed active exploitation yet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.