Cisco released security updates for Meeting Management, Secure Endpoint Connector on Linux, macOS, and Windows, Secure Endpoint Private Cloud, and BroadWorks to remediate multiple vulnerabilities, including a critical flaw in Cisco Meeting Management tracked as CVE-2025-20156. The bug affects authorization validation in the REST API and allows an authenticated remote attacker to escalate privileges to administrator, potentially taking full control of managed nodes. Cisco also patched CVE-2025-20165 in BroadWorks, where crafted SIP requests can trigger a denial of service.
ClamAV separately published patch releases 1.4.2 and 1.0.8 to fix CVE-2025-20128, a parser flaw in OLE2 file handling that affects all currently supported versions since ClamAV 1.0.0 and was identified by OSS-Fuzz. Cisco said the same ClamAV issue affects Secure Endpoint products, where crafted files could disable the antivirus component, and noted that proof-of-concept exploit code is available. The ClamAV releases also address a ClamOnAcc stability problem that could cause an infinite loop when a watched directory does not exist.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Cisco released security updates for Meeting Management, Secure Endpoint Connector for Linux, Mac, and Windows, Secure Endpoint Private Cloud, and BroadWorks to address multiple vulnerabilities. The advisory highlighted critical privilege-escalation flaw CVE-2025-20156 in Cisco Meeting Management, ClamAV-related CVE-2025-20128 affecting Secure Endpoint products, and denial-of-service flaw CVE-2025-20165 in BroadWorks.
ClamAV released versions 1.4.2 and 1.0.8 to fix CVE-2025-20128, described as a possible buffer overflow read bug in the OLE2 file parser affecting supported versions since 1.0.0. The release also credited OSS-Fuzz with identifying the issue and included a ClamOnAcc stability fix in 1.0.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.