cbcvebase.
CVE-2026-20045
published 2026-01-21

CVE-2026-20045: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-02-11
Exploited in the wild
EPSS
4.31%
90.1th percentile
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.

Affected

79 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager

Detection & IOCsextracted from sources · hover to see the quote

filenameciscocm.V14SU4a_CSCwr21851_remote_code_v1.cop.sha512
filenameciscocm.V15SU2_CSCwr21851_remote_code_v1.cop.sha512
filenameciscocm.V15SU3_CSCwr21851_remote_code_v1.cop.sha512
filenameciscocm.cuc.CSCwr29208_C0266-1.cop.sha512
  • Detect exploitation attempts by monitoring for sequences of crafted HTTP requests to the Cisco Unified CM web-based management interface, as the attack vector requires multiple sequential requests.
  • CVE-2026-20045 has been confirmed as actively exploited in the wild (zero-day); treat any anomalous HTTP traffic to Unified CM management interfaces as high-priority and correlate with privilege escalation to root.
  • CISA added CVE-2026-20045 to its Known Exploited Vulnerabilities (KEV) Catalog; prioritize detection and patching for Cisco Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance.
  • The vulnerability is classified as CWE-94 (Code Injection) via improper validation of user-supplied input in HTTP requests; tune WAF/IDS rules to flag unexpected input patterns in HTTP requests to Unified CM management endpoints.
  • Track Cisco bug IDs CSCwr21851, CSCwr29208, and CSCwr29216 in internal vulnerability management systems to identify unpatched assets across all affected product lines.
  • ·There are no workarounds available for CVE-2026-20045; patching is the only remediation. Unlike CVE-2026-20230 (WebDialer), there is no service-disable mitigation documented for this vulnerability.
  • ·Patch files for CVE-2026-20045 are version-specific; applying the wrong COP file to a mismatched release may fail or cause issues. The README must be reviewed before applying patches.
  • ·Cisco 12.5 train for both Unified CM/IM&P and Unity Connection has no direct patch; affected organizations must migrate to a fixed release.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.2HIGH
cisa9.8CRITICAL
vendor_cisco8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.