Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco Unified Contact Center Express Vulnerabilities Enables Remote Code Execution Attacks

## Cybersecurity: Vulnerabilities in Cisco Unified Contact Center Express

Cybersecurity: Vulnerabilities in Cisco Unified Contact Center Express

On Sun, Nov 5, 2025, a critical security advisory was issued regarding severe vulnerabilities in Cisco Unified Contact Center Express (Unified CCX). These vulnerabilities allow unauthenticated remote attackers to execute arbitrary commands, compromising affected systems. The advisory was updated on Mon, Nov 13, 2025.

Two distinct vulnerabilities have been identified in the Java Remote Method Invocation (RMI) process of Unified CCX:

CVE-2025-20354: Affects Cisco Unified CCX (Java RMI) with a CVSS score of 9.8. It allows unauthenticated attackers to upload files and run commands as root. CVE-2025-20358: Affects Cisco Unified CCX Editor with a CVSS score of 9.4. It enables attackers to bypass login and gain admin access for script execution.

The vulnerabilities affect Cisco Unified CCX regardless of device configuration. Cisco Unified Contact Center Enterprise (Unified CCE) and Packaged Contact Center Enterprise (Packaged CCE) are not affected. Vulnerable versions include Cisco Unified CCX 12.5 SU3 and earlier, as well as version 15.0.

On Sun, Nov 5, 2025, a critical security advisory was issued regarding severe vulnerabilities in Cisco Unified Contact Center Express (Unified CCX).
Anna Fields · Thehackingpost

Cisco has released fixed software addressing these issues: version 12.5 SU3 ES07 for the 12.5 branch and version 15.0 ES01 for the 15.0 branch. Cisco strongly recommends upgrading to the latest patched versions of software to mitigate the risk of remote code execution attacks.

The vulnerabilities were reported by security researcher Jahmel Harris of NATO Cyber Security Centre (NCSC). Currently, Cisco is not aware of any public exploits or active malicious use of these vulnerabilities in the wild. No workarounds are available for either vulnerability.

Advertisement

For more detailed information, please refer to the Cisco Security Advisory .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories