๐Ÿ”ด CVE-2026-20045

Critical remote code execution vulnerability in Cisco Unified Communications products allowing unauthenticated attackers to execute arbitrary commands via crafted HTTP requests to web management interfaces. Cisco confirms active exploitation attempts in the wild with potential for privilege escalation to root access.

โ† Back to Overview
HIGH_RISK
Risk Level
T1190
MITRE Technique
8.2
CVSS Score
NETWORK
Attack Vector
HIGH
Deployment Risk

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-01-21

Added to CISA KEV: 2026-01-21 0 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence

Key Sources:

  • Cisco Unified Communications Products Remote Code Execution...

    An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.

  • CVE-2026-20045 - High Vulnerability - TheHackerWire

    An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected ...

  • Known Exploited Vulnerabilities Catalog

    CVE-2026-20805. Microsoft Windows Information Disclosure Vulnerability: ยท Related CWE: CWE-200. Known To Be Used in Ransomware Campaigns? Unknown ; CVE-2025-8110.