Cisco Webex bug lets hackers gain code execution via meeting links
A high-severity Webex vulnerability that enables unauthenticated attackers to obtain client-side remote code execution using fraudulent meeting invite links has been patched by Cisco.
A security issue in the Webex custom URL parser, identified as CVE-2025-20236, allows threat actors to carry out arbitrary instructions on systems running unpatched software in low complexity attacks by deceiving users into downloading arbitrary files.
In a security advisory published this week, Cisco clarified that this vulnerability results from inadequate input validation when the Cisco Webex App analyzes a meeting invite URL.
By convincing a user to click on a well constructed meeting invite link and download random files, an attacker could take advantage of this vulnerability read more about Ci...

