Code Injection in Cisco Systems, Inc products - CVE-2026-20045

 

Code Injection in Cisco Systems, Inc products - CVE-2026-20045

Published: January 21, 2026 / Updated: February 6, 2026


Vulnerability identifier: #VU121911
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20045
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation when handling HTTP requests. A remote attacker can send a specially crafted HTTP request and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition
Cisco Unified Communications Manager IM & Presence Service
Cisco Unity Connection

How to mitigate CVE-2026-20045

Install updates from vendor's website.

Cisco Unified Communications Manager - update to 14SU5
Cisco Unified Communications Manager Session Management Edition - update to 14SU5
Cisco Unified Communications Manager IM & Presence Service - update to 14SU5
Cisco Unity Connection - update to 14SU5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins