Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access
Cisco has identified a critical zero-day remote code execution (RCE) vulnerability, designated CVE-2026-20045, which is being actively exploited. This vulnerability affects key Cisco Unified Communications products, allowing unauthenticated attackers to…
Cisco has identified a critical zero-day remote code execution (RCE) vulnerability, designated CVE-2026-20045, which is being actively exploited. This vulnerability affects key Cisco Unified Communications products, allowing unauthenticated attackers to execute arbitrary commands on the underlying operating system, potentially obtaining root access.
The vulnerability arises from improper validation of user-supplied input in HTTP requests to the web-based management interface. Attackers can send crafted HTTP requests that bypass authentication, execute commands at the user level, and escalate privileges to root. Cisco has rated this vulnerability as Critical, based on its Security Impact Rating (SIR), due to the associated root-level risks.
No workarounds are currently available. Exploitation requires network access to the management interface, which is common in enterprise VoIP setups exposed via firewalls or VPNs.
This vulnerability impacts the following Cisco products, regardless of configuration:
Unified CM - Bug ID: CSCwr21851 Unified CM SME - Bug ID: CSCwr21851 Unified CM IM&P - Bug ID: CSCwr29216 Unity Connection - Bug ID: CSCwr29208 Webex Calling Dedicated Instance - Bug ID: CSCwr21851
Products such as Contact Center SIP Proxy and Unified CCE are confirmed to be unaffected. For complete details, refer to the advisory .
Cisco has released updates and patches . Users should migrate or apply version-specific fixes and consult patch READMEs for guidance.
Cisco has identified a critical zero-day remote code execution (RCE) vulnerability, designated CVE-2026-20045, which is being actively exploited.
Release First Fixed Release
12.5 Migrate to fixed release
14 14SU5 or 14SU4a patch
15 15SU4 (Mar 2026) or 15SU2/3 patches
Release First Fixed Release
12.5 Migrate to fixed release
14 14SU5 or 14SU4 patch
15 15SU4 (Mar 2026) or 15SU3 patch
PSIRT validates only the listed releases.
Cisco PSIRT has observed real-world exploitation of this vulnerability, with attackers likely using automated scanners to find exposed interfaces. Enterprises with vulnerable VoIP/UC deployments are at high risk, especially in hybrid work environments. It is crucial to apply patches immediately, restrict management interfaces to trusted IPs via firewalls, and monitor logs for unusual HTTP requests. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog.
The vulnerability was reported by an external researcher, who was acknowledged by Cisco in the advisory. This incident highlights the risks associated with zero-day vulnerabilities like CVE-2026-20045, particularly in Unified Communications platforms, amidst increasing RCE trends.
Based on reporting by Cyber Security News.
