Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2330 articles · 161069 vulns · 36/41 feeds (7d)
← Back to list
6.1
CVE-2026-20233EXPLOITED
cis · webex meetings

Cisco Webex Meetings Cross-Site Scripting Vulnerability

Description

A vulnerability marked as problematic has been reported in Cisco Webex Meetings. This affects an unknown part of the component Web-based User Interface. The manipulation leads to cross site scripting. This vulnerability is listed as CVE-2026-20233. The attack may be initiated remotely. There is no available exploit. It is suggested to upgrade the affected component.

Affected Products

VendorProductVersions
ciswebex meetings39.7.7, 39.9, 40.4.10, 39.6, 40.6.2, 39.8.2, 39.8.4, 40.1, 39.11, 39.7.4, 39.9.1, 40.4, 40.6, 39.7, 39.8, 39.8.3, 40.2, 39.10, 42.6, 42.7, 42.8, 42.9, 42.10, 42.11, 42.12, 43.1, 43.2, 43.3, 43.4, 43.4.1, 43.4.2, 43.5.0, 43.6.0, 43.6.1, 43.7, 43.8, 43.9, 43.10, 43.11, 43.12, 44.1, 44.2, 44.3, 44.4, 44.5, 44.6, 44.7, 44.8, 44.9, 44.10, 44.11, 44.12, 45.1, 45.2, 45.3, 45.4

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ciswebexcert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-jw3NeQzS

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [mittel] Cisco WebEx Meetings: Schwachstelle ermöglicht Cross-Site Scripting
→ No new info (linked only)
Tier D
Heise Security4d ago
Cisco stopft kritische Lücke in Unified CM und mehr
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-20233 | Cisco Webex Meetings up to 45.4 Web-based User Interface cross site scripting (cisco-sa-webex-xss-jw3NeQzS)
→ No new info (linked only)
CVSS 3.16.1 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-79
PublishedJun 3, 2026
Last enriched5d agov2
Trending Score35
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20182EXPKEV
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Trending: 110
HIGHCVE-2026-20245EXP
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
Trending: 90
CRITICALCVE-2026-20230EXP
CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma
Trending: 58
HIGHCVE-2026-20175EXP
Cisco Finesse File Inclusion Vulnerability
Trending: 33
CRITICALCVE-2026-20223EXP
Cisco Secure Workload Unauthorized API Access Vulnerability
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 3, 2026
Discovered by ZDM
Jun 3, 2026
Actively Exploited
Jun 3, 2026
Updated: description, severity, activelyExploited
Jun 3, 2026

Version History

v2
Last enriched 5d ago
v2Tier C5d ago

Updated vendor to Cisco, severity to HIGH, marked as actively exploited, and provided a new description.

descriptionseverityactivelyExploited
via VulDB
v15d ago

Initial creation