ZeroHour

CVE-2026-20281

mass

Unauthenticated Memory-Leak DoS in Cisco SIP Software for IP and Desk Phones

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-20281 is a memory-management flaw (CWE-401) in the Cisco Session Initiation Protocol (SIP) Software running on the Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875, where HTTP packets are not properly released from memory. An unauthenticated, remote attacker can trigger it by sending a continuous stream of crafted HTTP packets to an affected phone, causing the device to consume memory without freeing it. A successful attack results in a denial-of-service condition on the handset that persists until an administrator manually reboots the device, with no confidentiality or integrity impact. Only phones registered to Cisco Unified Communications Manager (Unified CM) with Web Access enabled are exploitable, and Web Access is disabled by default, so a large share of deployments is likely unaffected. There is currently no evidence of exploitation, no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates roughly a 0.3% chance of exploitation within 30 days.

What to do: Inventory Unified CM registrations to identify phones running Cisco SIP Software and check whether Web Access is enabled; disabling Web Access on handsets that do not need it is an effective interim mitigation. Apply the fixed Cisco SIP Software release when Cisco publishes its advisory (scheduled for September 2, 2026, per its advance notification), and manually reboot any handset showing signs of memory exhaustion to restore service.

Affected
Cisco Desk Phone 9800 Series running Cisco SIP Software
Cisco IP Phone 7800 Series running Cisco SIP Software
Cisco IP Phone 8800 Series running Cisco SIP Software
Cisco Video Phone 8875 running Cisco SIP Software
Estimated exposure
massmillions of deployed handsets worldwide, with the directly exploitable subset (Unified CM-registered, Web Access enabled) plausibly in the hundreds of… — Cisco's 7800/8800 series are among the most widely deployed enterprise desk phones globally with an installed base in the millions, but the requirements that the phone be registered to Unified CM and have Web Access enabled (off by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.

Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.

Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.