Cisco fixed actively exploited Unified Communications zero day
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20029 | A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticate A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information. This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials. NVD description · AI analysis pending | 4.9 | 6% | — | — | ||
| CVE-2026-20045 | Unauthenticated RCE to root in Cisco Unified Communications products CVE-2026-20045 is an unauthenticated, remote command-execution flaw in Cisco Unified Communications Manager (including Session Management Edition), Unified CM IM & Presence Service, Unity Connection, and Webex Calling Dedicated Instance. It is caused by improper validation of user-supplied input in HTTP requests, and is triggered by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit gives the attacker user-level access to the underlying operating system, which can then be elevated to root — the reason Cisco assigned a Critical Security Impact Rating on top of the 9.8 CVSS score. The affected products are core enterprise call-control and voicemail platforms used by large organizations, plus Cisco-hosted Webex Calling Dedicated Instances. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-21 and news reports describe active probing, though no public proof-of-concept code is known and ransomware use is listed as unknown. Do: Upgrade all five affected products (Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance) to the fixed releases listed in Cisco's advisory, as this data does not specify version numbers. Until patched, restrict access to the web-based management interface to trusted management networks and monitor affected servers for suspicious HTTP request sequences and webshells. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use, following the KEV listing of 2026-01-21. | 9.8 | 4% | KEV |
| large≈ tens of thousands of enterprise deployments, likely on the order of 100,000+ Unified CM/Unity Connection servers, with thousands of management interfaces… |
Full article410 words · extracted from securityaffairs.com · click to collapse

Cisco patched a critical zero-day RCE flaw (CVE-2026-20045) in Unified Communications and Webex Calling that is actively exploited in the wild.
Cisco patched a critical zero-day remote code execution flaw, tracked as CVE-2026-20045 (CVSS score of 8.2), actively exploited in attacks.
An unauthenticated, remote attacker can exploit the flaw to execute arbitrary commands on the underlying operating system of an affected device.
The bug affected Cisco Unified CM, Unified CM SME, IM & Presence, Unity Connection, and Webex Calling Dedicated Instance.
“This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device.” reads the advisory. “A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.”
Below are impacted versions:
Unified CM, Unified CM IM&P, Unified CM SME, and Webex Calling Dedicated Instance
| Cisco Unified CM, Unified CM IM&P, Unified CM SME, and Webex Calling Dedicated Instance Release | First Fixed Release |
|---|---|
| 12.5 | Migrate to a fixed release. |
| 14 | 14SU5 or apply patch file:1 ciscocm.V14SU4a_CSCwr21851_remote_code_v1.cop.sha512 |
| 15 | 15SU4 (Mar 2026) or apply patch file:1 ciscocm.V15SU2_CSCwr21851_remote_code_v1.cop.sha512 ciscocm.V15SU3_CSCwr21851_remote_code_v1.cop.sha512 |
1. Patches are version-specific. Consult the README attached to the patch for details.
Unity Connection
| Cisco Unity Connection Release | First Fixed Release |
|---|---|
| 12.5 | Migrate to a fixed release. |
| 14 | 14SU5 or apply patch file:1 ciscocm.cuc.CSCwr29208_C0266-1.cop.sha512 |
| 15 | 15SU4 (Mar 2026) or apply patch file:1 ciscocm.cuc.CSCwr29208_C0266-1.cop.sha512 |
1. Patches are version-specific. Consult the README attached to the patch for details.
The networking giant confirmed that there are no workarounds that address this vulnerability.
“The Cisco PSIRT is aware of attempted exploitation of this vulnerability in the wild. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” concludes the advisory.
Early January, Cisco addressed a medium-severity vulnerability, tracked as CVE-2026-20029 (CVSS score: 4.9), in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) after a public PoC exploit was disclosed.
The vulnerability resides in the licensing feature of Cisco ISE and ISE-PIC due to improper XML parsing in the web management interface. An authenticated remote attacker with administrative privileges could exploit it by uploading a malicious file, enabling the reading of arbitrary files on the underlying operating system that should not be accessible, even to administrators.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2026-20045)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187177/security/cisco-fixed-actively-exploited-unified-communications-zero-day.html