Critical Cisco UCCX flaw lets attackers run commands as root
ID: 11fa9b0a-788d-5c03-b466-0d558edd14b7
STIX ID: report--11fa9b0a-788d-5c03-b466-0d558edd14b7
Feed Name: Bleeping Computer
Cisco released patches for critical vulnerabilities in Unified Contact Center Express—most notably CVE-2025-20354, an unauthenticated Java RMI flaw enabling arbitrary command execution as root—and an authentication-bypass in the CCX Editor that can create and run admin scripts; Cisco published fixed release versions and urges administrators to upgrade immediately. The advisory also highlights a high-severity Cisco ISE DoS issue (CVE-2025-20343) and other Contact Center product flaws, while noting PSIRT has not observed public exploit code or confirmed in-the-wild exploitation for these specific issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
