ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Fixes Actively Exploited Zero-Day CVE-2026

criticalExploit / PoC exploited in the wildimportance 60CVE-2026-20045CVE-2025-20393

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
CVE-2026-20045
Unauthenticated RCE to root in Cisco Unified Communications products

CVE-2026-20045 is an unauthenticated, remote command-execution flaw in Cisco Unified Communications Manager (including Session Management Edition), Unified CM IM & Presence Service, Unity Connection, and Webex Calling Dedicated Instance. It is caused by improper validation of user-supplied input in HTTP requests, and is triggered by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit gives the attacker user-level access to the underlying operating system, which can then be elevated to root — the reason Cisco assigned a Critical Security Impact Rating on top of the 9.8 CVSS score. The affected products are core enterprise call-control and voicemail platforms used by large organizations, plus Cisco-hosted Webex Calling Dedicated Instances. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-21 and news reports describe active probing, though no public proof-of-concept code is known and ransomware use is listed as unknown.

Do: Upgrade all five affected products (Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance) to the fixed releases listed in Cisco's advisory, as this data does not specify version numbers. Until patched, restrict access to the web-based management interface to trusted management networks and monitor affected servers for suspicious HTTP request sequences and webshells. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use, following the KEV listing of 2026-01-21.

9.84% KEV
  • Cisco Unified Communications Manager (Unified CM)
  • Cisco Unified Communications Manager Session Management Edition (Unified CM SME)
  • Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P)
  • +2 more
large≈ tens of thousands of enterprise deployments, likely on the order of 100,000+ Unified CM/Unity Connection servers, with thousands of management interfaces…
Full article430 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 22, 2026Vulnerability / Zero-Day

Cisco has released fresh patches to address what it described as a "critical" security vulnerability impacting multiple Unified Communications (CM) products and Webex Calling Dedicated Instance that it has been actively exploited as a zero-day in the wild.

The vulnerability, CVE-2026-20045 (CVSS score: 8.2), could permit an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system of a susceptible device.

"This vulnerability is due to improper validation of user-supplied input in HTTP requests," Cisco said in an advisory. "An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root."

The critical rating for the flaw is due to the fact that its exploitation could allow for privilege escalation to root, it added. The vulnerability impacts the following products -

  • Unified CM
  • Unified CM Session Management Edition (SME)
  • Unified CM IM & Presence Service (IM&P)
  • Unity Connection
  • Webex Calling Dedicated Instance

It has been addressed in the following versions -

Cisco Unified CM, CM SME, CM IM&P, and Webex Calling Dedicated Instance -

  • Release 12.5 - Migrate to a fixed release
  • Release 14 - 14SU5 or apply patch file: ciscocm.V14SU4a_CSCwr21851_remote_code_v1.cop.sha512
  • Release 15 - 15SU4 (Mar 2026) or apply patch file: ciscocm.V15SU2_CSCwr21851_remote_code_v1.cop.sha512 or ciscocm.V15SU3_CSCwr21851_remote_code_v1.cop.sha512

Cisco Unity Connection

  • Release 12.5 - Migrate to a fixed release
  • Release 14 - 14SU5 or apply patch file: ciscocm.cuc.CSCwr29208_C0266-1.cop.sha512
  • Release 15 - 15SU4 (Mar 2026) or apply patch file: ciscocm.cuc.CSCwr29208_C0266-1.cop.sha512

The networking equipment major also said it's "aware of attempted exploitation of this vulnerability in the wild," urging customers to upgrade to a fixed software release to address the issue. There are currently no workarounds. An anonymous external researcher has been credited with discovering and reporting the bug.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-20045 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by February 11, 2026.

The discovery of CVE-2026-20045 comes less than a week after Cisco released updates for another actively exploited critical security vulnerability affecting AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager (CVE-2025-20393, CVSS score: 10.0) that could permit an attacker to execute arbitrary commands with root privileges.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/01/cisco-fixes-actively-exploited-zero-day.html