Syslog Logging & ASP.NET /Kestrel CVE-2025-55315.

We’ve released a Hotfix Build 20.0.7.1060 for Update 7 that addresses a syslog logging issue and includes the latest Microsoft ASP.NET Core runtime patches.

  • Syslog Logging Bug Fix - Resolves an issue where sip-related messages about SIP Registrations were being reported to syslog.
  • ASP.NET / Kestrel Security Update (CVE-2025-55315) - Updates the Microsoft ASP.NET Core runtime and Kestrel packages to the latest patched versions.
    • The Microsoft security update primarily prevents vulnerability-scanners false positives and keeps the 3CX platform aligned with Microsoft latest security guidance. Although Microsoft has stated that exploitation of this issue is unlikely in typical deployments, we strongly recommend updating to Update 7 to stay compliant and up to date with Microsoft’s patched runtime.

How to Update

  • Automatic Updates Enabled: The system will automatically install the Update 7 Hotfix.
  • Automatic Updates Disabled:
    • Open the Admin Console → Updates.
    • Install the “Update 7 - 20.0.7.1060