CVE-2026-20045 is a critical remote code execution (RCE) vulnerability affecting multiple Cisco Unified Communications products, including Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance. This flaw stems from improper input validation in HTTP requests, allowing an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. A successful exploit grants user-level access, which can then be escalated to root privileges, posing a severe risk to affected systems. The vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Cisco has assigned a Security Impact Rating (SIR) of Critical, emphasizing the potential for privilege escalation to root. This zero-day vulnerability is actively exploited in the wild, as confirmed by Cisco and various media outlets. While no public Metasploit, Nuclei, or ExploitDB modules are currently available, the high level of community discussion (31 mentions) and media coverage (5 articles) indicate significant attention and concern regarding its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.5, < 14su5CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:* | ||
>= 12.5, < 14su5CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:* | ||
>= 15.0, <= 15su3aCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:-:*:*:* | ||
>= 15.0, <= 15su3aCPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager:*:*:*:*:session_management:*:*:* | ||
>= 12.5, < 14su5CPE matchmatch criteria | cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.