CVE-2026-20045

9.5 CISA KEV

Cisco · Unified Communications Manager

An unauthenticated remote code execution vulnerability exists in Cisco Unified Communications products due to improper HTTP request validation, allowing attackers to gain root access.

Executive summary

Cisco Unified Communications products are vulnerable to unauthenticated remote code execution that is currently being actively exploited in the wild.

Vulnerability

This is a code injection vulnerability (CWE-94) triggered by the improper validation of user-supplied input in HTTP requests. An unauthenticated remote attacker can exploit this via the web-based management interface to execute arbitrary commands, eventually escalating privileges to root.

Business impact

Successful exploitation poses a catastrophic risk to business operations, as it grants an attacker total control over critical communication infrastructure. With root-level access, malicious actors can intercept communications, exfiltrate sensitive data, or deploy persistent backdoors within the corporate network. The 9.5 CVSS score reflects the critical nature of this flaw, which is further amplified by confirmed active exploitation in the wild.

Remediation

Immediate Action: Apply the vendor-provided security patches immediately per the official Cisco security advisory. If patching is not feasible, restrict access to the web-based management interface to trusted administrative networks only.

Proactive Monitoring: Monitor management interface logs for unusual HTTP request patterns, specifically those containing unexpected characters or command-injection sequences.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated signatures to filter and block malicious HTTP requests targeting the management interface.

Exploitation status

Public Exploit Available: Yes, multiple public proof-of-concept repositories exist on GitHub.

Analyst recommendation

Given the critical severity and confirmed active exploitation of this vulnerability, immediate patching of all affected Cisco systems is mandatory. Organizations must prioritize this update above other non-critical maintenance tasks to prevent full system compromise and potential lateral movement within the network.

More Cisco CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Analyst report written

Sources