Junglewise Threat Intelligence

CVE-2026-20045: Cisco Unified Communications Products code injection in management interface

CVE-2026-20045 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-01-21

Technologies: Cisco Unified Communications Manager, Cisco Unity Connection. Vendors: Cisco.

Executive brief

Cisco Unified Communications products, which manage corporate telephony, messaging, and collaboration services, are affected by a critical security flaw. An unauthenticated attacker can remotely take full control of the underlying server by sending malicious web requests. This could lead to a total compromise of the communication system, allowing attackers to intercept data, disrupt operations, or gain a foothold in the corporate network.

Technical details

A code injection vulnerability (CWE-94) exists in the web-based management interface of several Cisco Unified Communications products due to improper validation of user-supplied input in HTTP requests. An unauthenticated, remote attacker can exploit this by sending a sequence of crafted HTTP requests to the affected device. Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system with user-level access and subsequently elevate privileges to root. This vulnerability is confirmed to be exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • Cisco Unified Communications Manager (Unified CM) 12.5 to 14su5, 15.0 to 15su3a
  • Cisco Unified Communications Manager Session Management Edition (Unified CM SME) 12.5 to 14su5, 15.0 to 15su3a
  • Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) 12.5 to 14su5, 15.0 to 15su3a
  • Cisco Unity Connection 12.5 to 14su5, 15.0 to 15su3a
  • Cisco Webex Calling Dedicated Instance

Timeline

  • 2026-01-21: advisory: Initial advisory published by Cisco
  • 2026-01-21: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-01-21: exploited: Reported as exploited in the wild

Related threats