CVE-2026-20045
published 2026-01-21CVE-2026-20045: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-02-11
Exploited in the wild
EPSS
4.31%
90.1th percentile
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for sequences of crafted HTTP requests to the Cisco Unified CM web-based management interface, as the attack vector requires multiple sequential requests. ↗
- →CVE-2026-20045 has been confirmed as actively exploited in the wild (zero-day); treat any anomalous HTTP traffic to Unified CM management interfaces as high-priority and correlate with privilege escalation to root. ↗
- →CISA added CVE-2026-20045 to its Known Exploited Vulnerabilities (KEV) Catalog; prioritize detection and patching for Cisco Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance. ↗
- →The vulnerability is classified as CWE-94 (Code Injection) via improper validation of user-supplied input in HTTP requests; tune WAF/IDS rules to flag unexpected input patterns in HTTP requests to Unified CM management endpoints. ↗
- →Track Cisco bug IDs CSCwr21851, CSCwr29208, and CSCwr29216 in internal vulnerability management systems to identify unpatched assets across all affected product lines. ↗
- ·There are no workarounds available for CVE-2026-20045; patching is the only remediation. Unlike CVE-2026-20230 (WebDialer), there is no service-disable mitigation documented for this vulnerability. ↗
- ·Patch files for CVE-2026-20045 are version-specific; applying the wrong COP file to a mismatched release may fail or cause issues. The README must be reviewed before applying patches. ↗
- ·Cisco 12.5 train for both Unified CM/IM&P and Unity Connection has no direct patch; affected organizations must migrate to a fixed release. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.2HIGH
cisa9.8CRITICAL
vendor_cisco8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h4w3-hxw6-99q7: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME)
ghsa_unreviewed·2026-01-21
CVE-2026-20045 [HIGH] CWE-94 GHSA-h4w3-hxw6-99q7: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME)
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then eleva
VulnCheck
Cisco Unified Communications Products Code Injection Vulnerability
vulncheck·2026·CVSS 8.2
CVE-2026-20045 [HIGH] CWE-94 Cisco Unified Communications Products Code Injection Vulnerability
Cisco Unified Communications Products Code Injection Vulnerability
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
Affected: Cisco Unified Communications Manager
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://sec.cloudapps.cisco
Cisco
Cisco Unified Communications Products Remote Code Execution Vulnerability
vendor_cisco·2026-01-22·CVSS 8.2
CVE-2026-20045 [HIGH] CWE-94 Cisco Unified Communications Products Remote Code Execution Vulnerability
Cisco Unified Communications Products Remote Code Execution Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to
CISA
Cisco Unified Communications Products Code Injection Vulnerability
cisa·2026-01-21·CVSS 9.8
CVE-2026-20045 [CRITICAL] CWE-94 Cisco Unified Communications Products Code Injection Vulnerability
Vulnerability: Cisco Unified Communications Products Code Injection Vulnerability
Affected: Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com
Cisco
Cisco Unified Communications Products Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20045 Cisco Unified Communications Products Remote Code Execution Vulnerability
CVE-2026-20045: Cisco Unified Communications Products Remote Code Execution Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow t
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Cisco warns of critical Unified CM flaw with PoC exploit code
blogs_bleepingcomputer·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco warns of critical Unified CM flaw with PoC exploit code
## Cisco warns of critical Unified CM flaw with PoC exploit code
## Sergiu Gatlan
Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges.
Cisco Unified CM (formerly known as Cisco CallManager) serves as the central control system for Cisco IP telephony systems, handling device management, call routing, and telephony features.
The vulnerability (tracked as CVE-2026-20230 ) can be exploited remotely by threat actors without privileges in low-complexity server-side request forgery (SSRF) attacks.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating
Hackernews
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
blogs_hackernews·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026-20230 , and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.
The flaw is a server-side request forgery. Unified CM and its Session Management Edition fail to validate certain HTTP requests properly, so a crafted request can push the server into writing arbitrary files onto
Bleepingcomputer
Cisco fixes Unified Communications RCE zero day exploited in attacks
blogs_bleepingcomputer·2026-01-21·CVSS 8.2
CVE-2026-20045 [HIGH] Cisco fixes Unified Communications RCE zero day exploited in attacks
## Cisco fixes Unified Communications RCE zero day exploited in attacks
## Lawrence Abrams
Cisco has fixed a critical Unified Communications and Webex Calling remote code execution vulnerability, tracked as CVE-2026-20045, that has been actively exploited as a zero-day in attacks.
Tracked as CVE-2026-20045, the flaw impacts Cisco Unified Communications Manager (Unified CM), Unified CM Session Management Edition (SME), Unified CM IM & Presence, Cisco Unity Connection, and Webex Calling Dedicated Instance.
"This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device," warns Cisco's advisory .
"A successful e
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
2026-01-21
Published
2026-01-21
Added to CISA KEV
Exploited in the wild