CVE-2025-20236Patch(cisco / webex_teams)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco webex_teams systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user. This vulnerability is due to insufficient input validation when Cisco Webex App processes a meeting invite link. An attacker could exploit this vulnerability by persuading a user to click a crafted meeting invite link and download arbitrary files. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the targeted user.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webex_teams

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
webex_teams

6 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 104-16
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Archange Shadow@Archange_Shadow
    Patch

    🚨 Cisco patched critical Webex flaw (CVE-2025-20236): client-side RCE via crafted meeting links in App v44.6 (<44.6.2.30589) & v44.7. Update now to block arbitrary code execution. #Cisco #Webex #Cybersecurity #RCE https://t.co/Qbgorrxnvs

    Post summary

    Cisco has released a patch for CVE‑2025‑20236, a client‑side RCE in Webex (v44.6 and v44.7); users are urged to update immediately to prevent arbitrary code execution.

    00000368
    339 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appciscowebex_teams44.6--
Appciscowebex_teams44.6.0.29928--
Appciscowebex_teams44.6.0.30148--
Appciscowebex_teams44.7--
Appciscowebex_teams44.7.0.30141--
Appciscowebex_teams44.7.0.30285--

Explore more