logo

Cisco Unity Connection Flaws Enable Full System Takeover

ID: 72a372c5-339b-54cc-94da-2666f96508ea

STIX ID: report--72a372c5-339b-54cc-94da-2666f96508ea

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

Cisco published a high-priority advisory for two independent vulnerabilities in Cisco Unity Connection: CVE-2026-20034, an authenticated remote code execution in the web management interface that can lead to arbitrary code execution as root, and CVE-2026-20035, an unauthenticated Server-Side Request Forgery in the Web Inbox feature that can be abused to send network requests from the affected device and probe internal networks; Cisco recommends applying the listed fixed releases or specific patches immediately as there are no effective workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.