Code Injection in Cisco Systems, Inc products - CVE-2026-20045
Published: January 21, 2026 / Updated: February 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when handling HTTP requests. A remote attacker can send a specially crafted HTTP request and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Cisco Unified Communications Manager Session Management Edition
Cisco Unified Communications Manager IM & Presence Service
Cisco Unity Connection
How to mitigate CVE-2026-20045
Cisco Unified Communications Manager Session Management Edition - update to 14SU5
Cisco Unified Communications Manager IM & Presence Service - update to 14SU5
Cisco Unity Connection - update to 14SU5