logo

Cisco fixed actively exploited Unified Communications zero day

ID: a105c997-1627-571a-a451-27f09f12ebb5

STIX ID: report--a105c997-1627-571a-a451-27f09f12ebb5

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco released patches for a critical, actively exploited zero-day RCE (CVE-2026-20045, CVSS 8.2) affecting Unified CM, IM & Presence, Unity Connection, Webex Calling Dedicated Instance and related Unified Communications products; attackers can send crafted HTTP requests to obtain user-level OS access and potentially escalate to root, and Cisco reports attempts at exploitation with no available workarounds, strongly advising upgrades to fixed releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.