ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045)

criticalVulnerability exploited in the wildimportance 60CVE-2026-20045

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20045
Unauthenticated RCE to root in Cisco Unified Communications products

CVE-2026-20045 is an unauthenticated, remote command-execution flaw in Cisco Unified Communications Manager (including Session Management Edition), Unified CM IM & Presence Service, Unity Connection, and Webex Calling Dedicated Instance. It is caused by improper validation of user-supplied input in HTTP requests, and is triggered by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit gives the attacker user-level access to the underlying operating system, which can then be elevated to root — the reason Cisco assigned a Critical Security Impact Rating on top of the 9.8 CVSS score. The affected products are core enterprise call-control and voicemail platforms used by large organizations, plus Cisco-hosted Webex Calling Dedicated Instances. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-21 and news reports describe active probing, though no public proof-of-concept code is known and ransomware use is listed as unknown.

Do: Upgrade all five affected products (Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance) to the fixed releases listed in Cisco's advisory, as this data does not specify version numbers. Until patched, restrict access to the web-based management interface to trusted management networks and monitor affected servers for suspicious HTTP request sequences and webshells. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use, following the KEV listing of 2026-01-21.

9.84% KEV
  • Cisco Unified Communications Manager (Unified CM)
  • Cisco Unified Communications Manager Session Management Edition (Unified CM SME)
  • Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P)
  • +2 more
large≈ tens of thousands of enterprise deployments, likely on the order of 100,000+ Unified CM/Unity Connection servers, with thousands of management interfaces…
Full article314 words · extracted from helpnetsecurity.com · click to collapse

Cisco has fixed a critical remote code execution vulnerability (CVE-2026-20045) in some of its unified communications solutions that’s being targeted by attackers in the wild, the company announced on Wednesday via a security advisory.

About CVE-2026-20045

CVE-2026-20045 is a code injection vulnerability stemming from improper validation of user-supplied input in HTTP requests.

“An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root,” Cisco says.

The company warns that its Product Security Incident Response Team (PSIRT) is aware of attempted exploitation of this vulnerability in the wild.

CVE-2026-20045, which was reported by an unnamed external researcher, affects:

  • Cisco Unified Communications Manager (CSCwr21851) – used mainly by large enterprises, government and public sector agencies, and organizations in regulated industries that run their own enterprise telephony infrastructure
  • Cisco Unified Communications Manager Session Management Edition (CSCwr21851) – used primarily by large enterprises with multiple CUCM clusters, regional deployments, or global routing complexity
  • Cisco Unified Communications Manager IM & Presence Service (CSCwr29216) – used by organizations that want real-time presence and messaging integrated with telephony
  • Cisco Unity Connection (CSCwr29208) – for organizations that need enterprise voicemail and messaging tied to their call infrastructure
  • Cisco Webex Calling Dedicated Instance (CSCwr21851) – for organizations that want a cloud-hosted, private version of CUCM-style calling

There are no workarounds to address this vulnerability, so Cisco “strongly recommends” that customers remediate the flaw as soon as possible by upgrading to a fixed software release or apply a patch file.

UPDATE (January 22, 2026, 06:40 a.m. ET):

CISA has added CVE-2026-20045 to its Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/21/cisco-enterprise-communications-cve-2026-20045/