Action required due to a web server configuration vulnerability.

3CX has released a security hotfix relating to a third party component. If your 3CX deployment is reachable from the public internet, apply the latest update immediately. 3CX hosted instances have already received the update.

Who is Affected

Deployment type Publicly accessible from the internet? Action required
Hosted by 3CX Managed by 3CX No customer action required. The fix has already been applied centrally.
On-premises No, protected behind firewall/VPN No immediate emergency action required, but update during the next maintenance window.
Self-hosted cloud No, protected behind firewall/VPN No immediate emergency action required, but update during the next maintenance window.
On-premises Yes At risk. Apply the hotfix immediately.
Self-hosted cloud Yes At risk. Apply the hotfix immediately.

Required Update

Apply the latest available update from the 3CX Admin Console.

  1. Log in to the 3CX Admin Console.
  2. Go to System > Updates.
  3. Select the latest available Update.
  4. Click Download and complete the installation.

Version-specific Guidance

Current version Required action
Version 20 Update 7 (earlier) Update to 20.0.8.1131
Version 20 Update 8 with automatic updates enabled The system will apply the fix automatically if you have automatic updates enabled.
If automatic updates are configured to run weekly or monthly, then you should update manually to 20.0.8.1131
Version 20 Update 8 with automatic updates disabled Update to 20.0.8.1131
Version 20 Update 9 Update to 20.0.9.987

Additional Information to Follow

We will provide a further update in the coming week with more details about the security hotfix.