logo

CVE-2026-20045 Actively Exploited Cisco Unified Communications Zero-Day Explained

ID: b0efb52a-98ae-56c9-9e6d-ebe71bb4fec8

STIX ID: report--b0efb52a-98ae-56c9-9e6d-ebe71bb4fec8

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-01-22

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Cisco released emergency patches for CVE-2026-20045, a critical unauthenticated remote code execution vulnerability affecting Unified Communications Manager, Webex Calling, and related Cisco UC products that is actively exploited in the wild; successful exploitation can lead to arbitrary command execution and escalation to root. Organizations are advised to apply patches immediately, restrict or block access to management interfaces, review logs for suspicious HTTP requests, and avoid exposing UC management interfaces to the internet; CISA has added the flaw to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.