Executive brief
Cisco Unified Communications products, which manage corporate telephony, messaging, and collaboration services, are affected by a critical security flaw. An unauthenticated attacker can remotely take full control of the underlying server by sending malicious web requests. This could lead to a total compromise of the communication system, allowing attackers to intercept data, disrupt operations, or gain a foothold in the corporate network.
Technical details
A code injection vulnerability (CWE-94) exists in the web-based management interface of several Cisco Unified Communications products due to improper validation of user-supplied input in HTTP requests. An unauthenticated, remote attacker can exploit this by sending a sequence of crafted HTTP requests to the affected device. Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system with user-level access and subsequently elevate privileges to root. This vulnerability is confirmed to be exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Cisco Unified Communications Manager (Unified CM) 12.5 to 14su5, 15.0 to 15su3a
- Cisco Unified Communications Manager Session Management Edition (Unified CM SME) 12.5 to 14su5, 15.0 to 15su3a
- Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) 12.5 to 14su5, 15.0 to 15su3a
- Cisco Unity Connection 12.5 to 14su5, 15.0 to 15su3a
- Cisco Webex Calling Dedicated Instance
Timeline
- 2026-01-21: advisory: Initial advisory published by Cisco
- 2026-01-21: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-01-21: exploited: Reported as exploited in the wild