CVE-2026-20045

Confirmed PUBLISHED

Cisco Unified Communications Products Remote Code Execution Vulnerability

Cisco · Cisco Unified Communications Manager, Cisco Unified Communications Manager IM and Presence Service, Cisco Unity Connection

1 day faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.2 High EPSS 4.3%

At a Glance

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.  This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.  Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.

cisa edge
CVE Published
Jan 21, 2026
Exploitation Reported
Jun 01, 2026
CVSS
8.2 High
EPSS
4.3%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

72 version rows · page 2 of 3

Vendor Product Version Status
Cisco
Cisco Unified Communications Manager

15.0.1.13013-1

Affected
Cisco
Cisco Unified Communications Manager

15.0.1.13014-1

Affected
Cisco
Cisco Unified Communications Manager

15.0.1.13015-1

Affected
Cisco
Cisco Unified Communications Manager

15.0.1.13016-1

Affected
Cisco
Cisco Unified Communications Manager

15.0.1.13017-1

Affected
Cisco
Cisco Unified Communications Manager

15SU3a

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU1

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU2

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU3

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU4

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

14

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU5

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

14SU1

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU6

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

14SU2

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

14SU2a

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU7

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

14SU3

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU8

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

15

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

15SU1

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

14SU4

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

12.5(1)SU9

Affected
Cisco
Cisco Unified Communications Manager IM and Presence Service

15SU2

Affected

CVE References

  • cisco-sa-voice-rce-mORhqY4b sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.