cbcvebase.
CVE-2020-26085
published 2021-01-07

CVE-2020-26085: Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs…

PriorityP359critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
2.52%
83.0th percentile
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscocisco_jabber
ciscojabber< 12.1.412.1.4
ciscojabber< 12.8.512.8.5
ciscojabber< 12.9.412.9.4
ciscojabber>= 12.5 < 12.5.312.5.3
ciscojabber>= 12.6 < 12.6.412.6.4
ciscojabber>= 12.7 < 12.7.312.7.3
ciscojabber>= 12.8 < 12.8.412.8.4
ciscojabber>= 12.9 < 12.9.312.9.3
ciscojabber>= 12.9 < 12.9.412.9.4
ciscojabber_desktop_and_mobile

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.