boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-20045

Cisco Unified Communications Products Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  L  N    8.2   .0454   91.3   YES
AFFECTED
  Product                                                       Versions      Fixed
  Cisco Unified Communications Manager                          12.5(1)SU2 –  —
  Cisco Unified Communications Manager IM and Presence Service  12.5(1) –     —
  Cisco Unity Connection                                        12.5(1) –     —
TIMELINE
  Oct 8   Reserved by cisco
  Jan 21  Added to CISA KEV, remediation due 2026-02-11
  Jan 21  Published (CNA: cisco)
CWE-94 · CNA: cisco · CVSS v3.1 · 2 references · KEV due February 11, 2026

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.  This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.  Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
October 8, 2025ReservedReserved by cisco
January 21, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-02-11
January 21, 2026PublishedPublished (CNA: cisco)

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
CiscoCisco Unified Communications Manager—12.5(1)SU2—
CiscoCisco Unified Communications Manager IM and Presence Service—12.5(1)—
CiscoCisco Unity Connection—12.5(1)—

Weaknesses

CWE-94

References (2)

Related

Authoritative record: CVE-2026-20045 at cve.org

Vendors: cisco

Weaknesses: CWE-94

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-20045 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.