logo

Cisco Unified Contact Center Express Vulnerabilities Enables Remote Code Execution Attacks

ID: 88f64136-0d3f-5ebe-b547-e6c4c16b58aa

STIX ID: report--88f64136-0d3f-5ebe-b547-e6c4c16b58aa

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Abinaya

...
...

Cisco published a critical advisory for two vulnerabilities in Unified Contact Center Express (CVE-2025-20354 and CVE-2025-20358) that enable unauthenticated remote code execution via Java RMI and an authentication bypass in the CCX Editor allowing admin script execution. Both flaws carry high CVSS scores (9.8 and 9.4), affect Unified CCX 12.5 SU3 and earlier and 15.0, and have fixes released (12.5 SU3 ES07 and 15.0 ES01); Cisco recommends immediate upgrading and currently reports no known public exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.