Cisco: Critical Meeting Management Bug Requires Urgent Patch
ID: 7d1ff60c-1062-5aea-81ad-efe45015e801
STIX ID: report--7d1ff60c-1062-5aea-81ad-efe45015e801
Feed Name: Dark Reading
Threat Score
Date Published: 2025-01-24
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
...
...
**Executive Summary:** Cisco released a patch for CVE-2025-20156, a critical (CVSS 9.9) privilege-escalation vulnerability in the Cisco Meeting Management REST API that allows authenticated video-operator users to gain administrator privileges on affected on-premises devices; versions 3.9 and earlier are vulnerable (upgrade to 3.9.1; 3.10 unaffected) and there are no workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
