logo

CVE-2026-20045: Critical Zero-Day in Cisco Products Is Actively Exploited in the Wild

ID: 495727f0-af2e-5936-a1ed-71bc9680c3d3

STIX ID: report--495727f0-af2e-5936-a1ed-71bc9680c3d3

Feed Name: SOC Prime Blog

Threat Score
85/100

Date Published: 2026-01-22

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Cisco patched a critical remote code execution vulnerability (CVE-2026-20045) in Unified CM, SME, IM&P, Unity Connection, and Webex Calling Dedicated Instance that allows attackers to execute commands and escalate to root; the flaw is being actively exploited in the wild, has no workaround, and was added to CISA's Known Exploited Vulnerabilities catalog, prompting urgent patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.