๐Ÿ”ด CVE-2026-20045

Critical remote code execution vulnerability in Cisco Unified Communications products allowing unauthenticated attackers to execute arbitrary commands via crafted HTTP requests to web management interfaces. Cisco confirms active exploitation attempts in the wild with potential for privilege escalation to root access.

โ† Back to Overview
HIGH_RISK
Risk Level
8.2
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-01-21

Added to CISA KEV: 2026-01-21 0 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2026-01-21)

Regarding CVE-2026-20045, here's what is known about its exploitation:

  • Internet-facing applications or services: The vulnerability affects the web-based management interface of affected devices. [2]
  • Evidence of active exploitation in the wild: There is no explicit mention of active exploitation in the wild in the provided information.
  • Attack vectors and exploitation methods: An attacker can exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface. [2]
  • Use in targeted attacks: The provided information does not specify if this vulnerability has been used in targeted attacks.
  • CISA Known Exploited Vulnerabilities status: CVE-2026-20045 is not listed on the CISA Known Exploited Vulnerabilities Catalog based on the provided search results. [3]
  • Technical details about internet exploitability: The exploit involves sending crafted HTTP requests to the management interface. A successful exploitation could allow an attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. [1] The vulnerability has a Security Impact Rating (SIR) of Critical due to the potential for privilege escalation to root. [1]

Sources

  1. Cisco Unified Communications Products Remote Code Execution...

    An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. Nโ€ฆ

  2. CVE-2026-20045 - High Vulnerability - TheHackerWire

    An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected ...

  3. Known Exploited Vulnerabilities Catalog

    CVE-2026-20805. Microsoft Windows Information Disclosure Vulnerability: ยท Related CWE: CWE-200. Known To Be Used in Ransomware Campaigns? Unknown ; CVE-2025-8110.