Cisco Unified Contact Center Express Vulnerabilities Enables Remote Code Execution Attacks
## Cybersecurity: Vulnerabilities in Cisco Unified Contact Center Express
Cybersecurity: Vulnerabilities in Cisco Unified Contact Center Express
On Sun, Nov 5, 2025, a critical security advisory was issued regarding severe vulnerabilities in Cisco Unified Contact Center Express (Unified CCX). These vulnerabilities allow unauthenticated remote attackers to execute arbitrary commands, compromising affected systems. The advisory was updated on Mon, Nov 13, 2025.
Two distinct vulnerabilities have been identified in the Java Remote Method Invocation (RMI) process of Unified CCX:
CVE-2025-20354: Affects Cisco Unified CCX (Java RMI) with a CVSS score of 9.8. It allows unauthenticated attackers to upload files and run commands as root. CVE-2025-20358: Affects Cisco Unified CCX Editor with a CVSS score of 9.4. It enables attackers to bypass login and gain admin access for script execution.
The vulnerabilities affect Cisco Unified CCX regardless of device configuration. Cisco Unified Contact Center Enterprise (Unified CCE) and Packaged Contact Center Enterprise (Packaged CCE) are not affected. Vulnerable versions include Cisco Unified CCX 12.5 SU3 and earlier, as well as version 15.0.
On Sun, Nov 5, 2025, a critical security advisory was issued regarding severe vulnerabilities in Cisco Unified Contact Center Express (Unified CCX).
Cisco has released fixed software addressing these issues: version 12.5 SU3 ES07 for the 12.5 branch and version 15.0 ES01 for the 15.0 branch. Cisco strongly recommends upgrading to the latest patched versions of software to mitigate the risk of remote code execution attacks.
The vulnerabilities were reported by security researcher Jahmel Harris of NATO Cyber Security Centre (NCSC). Currently, Cisco is not aware of any public exploits or active malicious use of these vulnerabilities in the wild. No workarounds are available for either vulnerability.
For more detailed information, please refer to the Cisco Security Advisory .
Based on reporting by Cyber Security News.
