• News/
  • https://www.theregister.com/2026/01/22/another_week_another_emergency_patch/

Another week, another emergency patch as Cisco plugs Unified Comms zero-day

The Register
·
Carly Page
·
Published Jan 22, 2026
·
Updated

Cisco has finally shipped a fix for a critical-rated zero-day in its Unified Communications gear, a flaw that's already being weaponized in the wild, and which CISA previously flagged as an emergency priority. The bug, tracked as CVE-2026-20045, lurks in the web-management interfaces of Cisco Unified Communications Manager (Unified CM), Session Management Edition (SME), IM & Presence Service (IM&P), Cisco Unity Connection, and Webex Calling Dedicated Instance platforms. It allows unauthenticated remote attackers to execute arbitrary code on the underlying operating system and potentially escalate to root. Cisco's Product Security Incident Response Team gave it a "Critical" severity rating, even though its CVSS base score sits in the "High" range, because successful exploits can lead to full system compromise. The networking giant said it is "aware of attempted exploitation of this vulnerability in the wild" and has urged customers to apply fixes immediately. Cisco hasn't said how many customers are affected, whether any data has been exfiltrated from affected environments, or who is behind these exploitation attempts. The firm did not immediately respond to The Register's questions. The issue sits in the management interface's HTTP handling and can be triggered without logging in. "This vulnerability is due to improper validation of user-supplied input in HTTP requests," Cisco explains in its advisory. "An attacker could exploit this vulnerability by sending a sequence of cra...

Read full article

Affected Software

5 affected components
Cisco Unified Communications Manager>=all
Cisco Session Management Edition>=all
Cisco IM & Presence Service>=all
Cisco Unity Connection>=all
Cisco Webex Calling Dedicated Instance>=all
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical-rated zero-day vulnerability in Cisco's Unified Communications products and the emergency patch released to address it.

2

What security implications are discussed in the article?

The article highlights the risk of the zero-day vulnerability being actively exploited in the wild, which poses a significant threat to users of Cisco's Unified Communications gear.

3

What products or software are affected by the vulnerability?

The affected products include Cisco Unified Communications Manager, Cisco Session Management Edition, Cisco IM & Presence Service, Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance.

4

Why was this vulnerability flagged as an emergency?

The vulnerability was flagged by CISA as an emergency due to its critical nature and the potential for widespread exploitation.

5

What action has Cisco taken in response to the vulnerability?

Cisco has released an emergency patch to fix the zero-day vulnerability in its Unified Communications products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203