logo

Multiple Cisco Unified CCX Flaws Allow Attackers to Execute Arbitrary Commands

ID: fdb15678-b6fb-546c-81d1-1e9a9c6342c3

STIX ID: report--fdb15678-b6fb-546c-81d1-1e9a9c6342c3

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-11-14

Date Updated: 2026-04-19

Author: AnuPriya

...
...

Cisco disclosed two critical unauthenticated Java RMI vulnerabilities in Cisco Unified Contact Center Express (CVE-2025-20354 and CVE-2025-20358): one permits arbitrary file upload and root-level remote code execution, and the other allows authentication bypass in the CCX Editor to create and run administrative scripts. Both have very high CVSS scores (9.8 and 9.4), affect CCX 12.5 SU3 and earlier and 15.0 and earlier, have no mitigations beyond upgrading, and fixed releases (12.5 SU3 ES07 and 15.0 ES01) have been published—organizations must prioritize immediate patching to avoid full contact-center compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.