Cisco Webex Services Cross-Site Scripting Vulnerabilities

🚨 SEVERITY: MEDIUM — CVSS 6.1 Security Advisory

TL;DR 📌

Cisco has identified multiple cross-site scripting (XSS) vulnerabilities in Cisco Webex Services that could allow an unauthenticated remote attacker to exploit users. The vulnerabilities have been addressed, and no user action is required for updates.

What happened 🕵️‍♂️

Multiple vulnerabilities in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. These vulnerabilities arise from improper filtering of user-supplied input. An attacker could exploit these vulnerabilities by persuading a user to follow a malicious link, which could lead to a successful XSS attack against the targeted user.

Affected products 🖥️

The vulnerabilities affect Cisco Webex, which is a cloud-based service.

Fixed software 🔧

Upgrade to at least the first fixed release in your train (or later):

Product / Release Train First Fixed Release Notes
ISE / ISE-PIC 1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address these vulnerabilities.

Risk in context 🎯

The highest CVSS score for these vulnerabilities is 6.1, classified as MEDIUM severity. While the risk is notable, Cisco has taken steps to mitigate the vulnerabilities, and there is currently no known public exploitation.

Fast facts ⚡

  • Advisory ID: cisco-sa-webex-xss-7teQtFn8
  • CVEs: CVE-2025-20250, CVE-2025-20246, CVE-2025-20247
  • CVSS Score: 6.1 (MEDIUM)
  • No user action required for updates.

For leadership 🧭

Executive summary. Cisco has fixed three cross-site scripting flaws in Webex that stemmed from improper filtering of user input, rated medium severity at 6.1 CVSS. Because Cisco hosts the fix, there is nothing to patch locally, but users should be aware that malicious links were the theoretical attack path.

Why it matters:

  • Webex is a cloud service, so the vulnerable component sits outside your own infrastructure and you cannot patch it directly.
  • The flaws stem from improper filtering of user-supplied input in Webex, the kind of gap that enables script injection through crafted links.
  • There are no workarounds, meaning the only mitigation prior to Cisco’s fix was user caution rather than any configuration change.
  • Three separate CVEs (CVE-2025-20246, CVE-2025-20247, CVE-2025-20250) affect the same service, indicating more than one distinct input-handling gap.

Now / Next / Later:

  • Now: Confirm your organisation’s Webex tenant is running current Cisco-hosted infrastructure; no local action is needed since Cisco has already applied the fix.
  • Next: Review internal guidance for Webex users on verifying meeting links and notifications before clicking, given the service’s reliance on hosted delivery of fixes.
  • Later: Track future Webex advisories from Cisco as part of routine SaaS vendor patch monitoring, since fixes here are entirely vendor-managed rather than something your team deploys.