CVE-2020-27610: Bigbluebutton

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automatically set up a firewall configuration to block external access.

Affected products

Published 2020-10-21. Last modified 2026-06-17.