logo

Cisco fixes Unified Communications RCE zero day exploited in attacks

ID: 0eb52a4c-fbd3-5385-95d0-c025c75b968a

STIX ID: report--0eb52a4c-fbd3-5385-95d0-c025c75b968a

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Cisco patched CVE-2026-20045, a critical remote code execution vulnerability in Cisco Unified Communications Manager, Unified CM SME, Unified CM IM & Presence, Cisco Unity Connection, and Webex Calling Dedicated Instance that has been observed exploited in the wild; successful exploitation can yield user-level access and escalation to root. Cisco released version-specific patches (README advised), stated there are no viable workarounds, and CISA added the CVE to its KEV catalog with a federal remediation deadline of February 11, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.