Cisco has finally shipped a fix for a critical-rated zero-day in its Unified Communications gear, a flaw that's already being weaponized in the wild, and which CISA previously flagged as an emergency priority. The bug, tracked as CVE-2026-20045, lurks in the web-management interfaces of Cisco Unified Communications Manager (Unified CM), Session Management Edition (SME), IM & Presence Service (IM&P), Cisco Unity Connection, and Webex Calling Dedicated Instance platforms. It allows unauthenticated remote attackers to execute arbitrary code on the underlying operating system and potentially escalate to root. Cisco's Product Security Incident Response Team gave it a "Critical" severity rating, even though its CVSS base score sits in the "High" range, because successful exploits can lead to full system compromise. The networking giant said it is "aware of attempted exploitation of this vulnerability in the wild" and has urged customers to apply fixes immediately. Cisco hasn't said how many customers are affected, whether any data has been exfiltrated from affected environments, or who is behind these exploitation attempts. The firm did not immediately respond to The Register's questions. The issue sits in the management interface's HTTP handling and can be triggered without logging in. "This vulnerability is due to improper validation of user-supplied input in HTTP requests," Cisco explains in its advisory. "An attacker could exploit this vulnerability by sending a sequence of cra...
Another week, another emergency patch as Cisco plugs Unified Comms zero-day
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article discusses a critical-rated zero-day vulnerability in Cisco's Unified Communications products and the emergency patch released to address it.
What security implications are discussed in the article?
The article highlights the risk of the zero-day vulnerability being actively exploited in the wild, which poses a significant threat to users of Cisco's Unified Communications gear.
What products or software are affected by the vulnerability?
The affected products include Cisco Unified Communications Manager, Cisco Session Management Edition, Cisco IM & Presence Service, Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance.
Why was this vulnerability flagged as an emergency?
The vulnerability was flagged by CISA as an emergency due to its critical nature and the potential for widespread exploitation.
What action has Cisco taken in response to the vulnerability?
Cisco has released an emergency patch to fix the zero-day vulnerability in its Unified Communications products.