A vulnerability has been discovered in Cisco Unified Communications Products which could allow for remote code execution. Cisco Unified Communications (UC) Products are an integrated suite of IP-based hardware and software that combine voice, video, messaging, and data into a single platform. Successful exploitation of this vulnerability could allow for remote code execution as root, which may lead to the complete compromise of the affected device.
THREAT INTELLIGENCE:
The Cisco PSIRT is aware of attempted exploitation of CVE-2026-20045 in the wild. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
SYSTEMS AFFECTED:
-
Unified CM (CSCwr21851)
-
Unified CM SME (CSCwr21851)
-
Unified CM IM&P (CSCwr29216)
-
Unity Connection (CSCwr29208)
-
Webex Calling Dedicated Instance (CSCwr21851)
RISK:
Government:
-
Large and medium government entities: High
-
Small government entities: Medium
Businesses:
-
Large and medium business entities: High
-
Small business entities: Medium
Home users: Low
TECHNICAL SUMMARY:
A vulnerability has been discovered in Cisco Unified Communications Products which could allow for remote code execution. Details of the vulnerability are as follows:
Tactic: Initial Access (TA0001):
Technique: Exploit Public-Facing Application (T1190):
-
A vulnerability in Cisco Unified Communications Products which could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. (CVE-2026-20045)
Successful exploitation of this vulnerability could allow for remote code execution as root, which may lead to the complete compromise of the affected device.
RECOMMENDATIONS:
We recommend the following actions be taken:
-
Apply appropriate updates provided by Cisco or other vendors which use this software to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
-
Safeguard 7.1 : Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
-

