logo

Cisco: Critical Meeting Management Bug Requires Urgent Patch

ID: 7d1ff60c-1062-5aea-81ad-efe45015e801

STIX ID: report--7d1ff60c-1062-5aea-81ad-efe45015e801

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-24

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

**Executive Summary:** Cisco released a patch for CVE-2025-20156, a critical (CVSS 9.9) privilege-escalation vulnerability in the Cisco Meeting Management REST API that allows authenticated video-operator users to gain administrator privileges on affected on-premises devices; versions 3.9 and earlier are vulnerable (upgrade to 3.9.1; 3.10 unaffected) and there are no workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.