logo

Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access

ID: 0a7f4669-c062-5899-9649-6e2d39925756

STIX ID: report--0a7f4669-c062-5899-9649-6e2d39925756

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-01-22

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Cisco disclosed a critical zero-day RCE (CVE-2026-20045) affecting multiple Unified Communications products, allowing unauthenticated attackers to send crafted HTTP requests to the web management interface to execute commands and escalate to root. Cisco PSIRT confirmed active exploitation, released patches for affected releases, noted no workarounds, and urged immediate patching and network access restrictions; CISA added it to the Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.