CVE-2026-20045Active Exploitation(cisco / unified_communications_manager)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch cisco unified_communications_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.  This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.  Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-11. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unified_communications_manager
  • unified_communications_manager_im_and_presence_service
  • unity_connection

Threat summary

  • Active exploitation appears in 24 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 40 mentions across 21 observed days

What's happening

  • Active exploitation reported across 24 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 16 signals
  • General: 6 classified signals
  • Peaked 3d ago at 6 mentions (2026-05-05); latest day: 2
  • 40 total mentions across 21 days

Affected systems

Vendors
Products
unified_communications_managerunified_communications_manager_im_and_presence_serviceunity_connection

Deep dive

Activity timeline40 mentions / 21d
02356Mentions · 2026-01-27: 2Mentions · 2026-01-28: 3Mentions · 2026-01-29: 3Mentions · 2026-01-30: 5Mentions · 2026-01-31: 1Mentions · 2026-02-01: 1Mentions · 2026-02-02: 1Mentions · 2026-02-04: 3Mentions · 2026-02-05: 1Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-02-11: 2Mentions · 2026-02-16: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-25: 1Mentions · 2026-02-28: 1Mentions · 2026-05-05: 6Mentions · 2026-06-20: 1Mentions · 2026-07-02: 1Mentions · 2026-07-13: 2PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-06-20: 1PoC Mentioned / Linked · 2026-07-02: 1PoC Mentioned / Linked · 2026-07-13: 2Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-07-13: 1Active Exploitation · 2026-01-27: 2Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-29: 2Active Exploitation · 2026-01-30: 3Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-04: 2Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-10: 1Active Exploitation · 2026-02-11: 2Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-02-28: 1Active Exploitation · 2026-05-05: 6Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 3Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-20: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 3Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-25: 1Technical Details · 2026-06-20: 1Technical Details · 2026-07-13: 201-2701-2901-3102-0202-0502-1002-1602-2002-2806-2007-13
Signal classification6 categories
Active Exploitation
1845.0%
Patch
717.5%
General
615.0%
Disclosure
512.5%
PoC
37.5%
Exploit
12.5%
Referenced assets49 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-272
Active Exploitation1Patch1
2026-01-283
Disclosure2Patch1
2026-01-293
Active Exploitation2Disclosure1
2026-01-305
Active Exploitation1General2Patch2
2026-01-311
General1
2026-02-011
Active Exploitation1
2026-02-021
Disclosure1
2026-02-043
Active Exploitation2General1
2026-02-051
Patch1
2026-02-091
Patch1
2026-02-102
Active Exploitation1Disclosure1
2026-02-112
Active Exploitation2
2026-02-161
General1
2026-02-191
General1
2026-02-201
Patch1
2026-02-251
Active Exploitation1
2026-02-281
Active Exploitation1
2026-05-056
Active Exploitation6
2026-06-201
PoC1
2026-07-021
PoC1
2026-07-132
Exploit1PoC1
Full discourse20 posts
  • Dark Web Intelligence@DailyDarkWeb
    PoC

    🌐 Cisco Unified Communications Alleged CVE-2026-20045 RCE Exploit Source Code Advertised on Underground Forum A threat actor is advertising what they claim to be source code and exploit material for CVE-2026-20045, a high-severity vulnerability affecting multiple Cisco Unified Communications products. According to the forum post, the actor claims: * Exploit targets CVE-2026-20045 * CVSS Score: 8.2 (High) * Unauthenticated Remote Code Execution (RCE) * Source code included * Exploit download available to forum members * Targets multiple Cisco Unified Communications platforms Allegedly Affected Products: * Cisco Unified Communications Manager (CUCM) * Cisco Unified CM Session Management Edition (SME) * Cisco Unified CM IM & Presence Service * Cisco Unity Connection * Cisco Webex Calling Dedicated Instance Potential Risks: * Remote code execution without authentication * Full system compromise of exposed communications infrastructure * Lateral movement into enterprise environments * Voice infrastructure disruption * Interception of communications and call management services * Persistence and privilege escalation opportunities following exploitation Analyst Note: At this stage, the forum post only claims to provide exploit source code and no technical validation has been observed. However, Cisco Unified Communications platforms are widely deployed across government, healthcare, finance, and enterprise environments. Any publicly available or privately traded RCE exploit targeting these systems would significantly increase the likelihood of opportunistic exploitation and mass scanning activity. #DDW #Intelligence #DarkWeb #Cisco

    Post summary

    A forum advertises source code for CVE‑2026‑20045, a high‑severity RCE vulnerability, yet no evidence of active exploitation or validated exploit code has been presented.

    35029149.0K
    198.1K followersView on X
  • Kaan@wkaandemir
    Disclosure

    Güvenlik Rehberi'ne taze güncelleme! 🔥 Artık repo OWASP Top 10 2025'le sınırlı değil; her ay yeni açıklar, tehditler ve pratik çözümlerle genişleyecek. Bu ay: OWASP notlarını detaylandırdım + şu açıkları ekledim: • Windows DWM info leak (CVE-2026-20805) • Windows Graphics EoP (CVE-2026-20822) • Linux mlx5e UAF (CVE-2026-23000) • Cisco CM RCE (CVE-2026-20045) • Apache Tika XXE (CVE-2025-66516) Yeni dokümanlar, checklist'ler ve önerilerle daha güçlü.

    Post summary

    The update announces a list of new CVEs with brief technical descriptors but does not provide PoC, exploit code, or patch information.

    11061500
    1.8K followersView on X
  • Hunt.io@Huntio
    Patch

    ⚠️ Cisco Fixes Actively Exploited Zero-Day in Unified Communications & Webex https://www.bleepingcomputer.com/news/security/cisco-fixes-unified-communications-rce-zero-day-exploited-in-attacks/ Cisco has released urgent patches for a critical zero-day vulnerability tracked as CVE-2026-20045 that is being actively exploited in the wild against its Unified Communications Manager (Unified CM), Unity Connection, IM & Presence, and Webex Calling Dedicated Instance platforms. The flaw stems from improper validation of user-supplied input in HTTP requests to the web-based management interface, allowing unauthenticated attackers to send crafted requests, execute arbitrary commands on the underlying OS, and escalate privileges to root. If you operate Cisco Unified Communications or Webex infrastructure, apply the latest security updates immediately, isolate the web-based management interfaces from untrusted networks, and monitor for anomalous HTTP management traffic to detect exploitation attempts. #Cisco #ZeroDay #Webex #ThreatHunting

    Post summary

    Cisco released urgent patches for CVE‑2026‑20045, a critical zero‑day RCE that is actively being exploited, and urges immediate update and isolation of affected management interfaces.

    01071536
    4.8K followersView on X
  • Blue Team News@blueteamsec1
    Patch

    Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex http://dlvr.it/TR4RSV #Cisco #CyberSecurity #ZeroDay #CVE202620045 #Webex https://t.co/UAu3pTalxa

    Post summary

    Cisco released a patch for the actively exploited zero‑day CVE‑2026‑20045 affecting Unified CM and Webex.

    11030507
    54.6K followersView on X
  • Criminal IP Japan@CriminalIP_JP
    General

    🫖 サイバーセキュリティ・ティータイム:2026年1月の主要トピックを抽出​ 2026年1月に目立ったのは、新しいゼロデイや高度な手法ではなく、外部に露出した管理接点(Attack Surface)がそのまま攻撃成立条件になっていた点でした。​ ​・ #GNUInetUtils telnetd 認証回避(CVE-2026-24061)​ ・ #Fortinet #FortiGate 自動化された設定攻撃の急増​ ・ #Cisco Unified CM ゼロデイRCE(CVE-2026-20045)​ 鍵となったのは「脆弱性」そのものではなく、外部に到達可能だったかどうかでした。​ 👉全文はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/7918

    Post summary

    The tweet enumerates two CVEs with basic vulnerability descriptions, but offers no evidence of exploits, PoC, or active attacks.

    00050239
    1.4K followersView on X
  • Enable Security@enablesecurity
    Active Exploitation

    1/ January RTCSec newsletter is out. Packed edition to kick off 2026. Cisco UCM zero-day (CVE-2026-20045) is being actively exploited. CISA added it to KEV. First fixed release for 14.x is 14SU5; 15SU4 is scheduled for March. https://www.enablesecurity.com/newsletter/2026-01-rtcsec-news/

    Post summary

    The post announces that Cisco UCM CVE-2026-20045 is actively exploited and provides patch release details, indicating an ongoing exploitation threat.

    10030120
    344 followersView on X
  • Misbar | مسبار@MisbarSec
    General

    سامسونج تقترب من موافقة NVIDIA على ذاكرة HBM4 أخبار تفيد بأن سامسونج على وشك الحصول على موافقة NVIDIA النهائية لجيل جديد من ذاكرة HBM4. هذه الذاكرة تعتبر نقلة نوعية في مجال الذكاء الاصطناعي. هناك بعض الثغرات الأمنية التي تم ذكرها مثل CVE-2026-21509 و CVE-2026-20045. 💡 خطوات الحماية: - تابع التحديثات الأمنية للأجهزة والبرامج. - طبق أقوى معايير إدارة الوصول. - عزز أنظمة المراقبة للكشف المبكر عن أي نشاط مشبوه. 🔗 https://securityonline.info/the-ai-throne-reclaimed-samsung-nears-final-nvidia-seal-of-approval-for-game-changing-hbm4/ #الأمن_السيبراني #سامسونج #NVIDIA #HBM4 #ذكاء_اصطناعي

    Post summary

    The passage reports Samsung’s progress toward HBM4 approval and references two CVEs, but provides no details on exploitation, patches, or technical specifics.

    00030132
    51 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:14 UTC: Thread live on @lyrie_ai. CVE-2026-20045 added to CISA KEV: Cisco Unified Communications Manager

    Post summary

    CVE-2026-20045 was added to the CISA KEV list for Cisco Unified Communications Manager, indicating it is being actively exploited in the wild.

    2000057
    151 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    APT28 تشن حملة "Operation Neusploit" عبر ثغرات Office مجموعة APT28، المعروفة أيضًا باسم Fancy Bear، عادت بحملة جديدة تستهدف أوروبا الوسطى والشرقية. تستغل المجموعة ثغرات في برامج Office لتنفيذ هجماتها. هذه الثغرات المحددة هي CVE-2026-24858، CVE-2026-21509، و CVE-2026-20045. 💡 حماية: - حدثوا أنظمة Office الخاصة بكم فور توفر التحديثات. - كن حذرًا من مرفقات ورسائل البريد الإلكتروني المشبوهة. - طبق مبدأ أقل امتياز صلاحيات للمستخدمين. 🔗 https://securityonline.info/fancy-bear-returns-apt28-exploits-office-flaw-in-operation-neusploit/ #الأمن_السيبراني #APT28 #OperationNeusploit #Office

    Post summary

    APT28 is reported to be actively exploiting new Office CVEs (CVE-2026-24858, CVE-2026-21509, CVE-2026-20045) in a campaign targeting Europe, with advisories urging users to update Office promptly.

    0002097
    51 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    CVE-2026-20045. 0day Intel: 🌐 Cisco Unified Communications Alleged CVE-2026-20045 RCE Exploit Source Code A

    Post summary

    The post asserts the availability of exploit source code for CVE‑2026‑20045, indicating potential exploitation readiness but lacking evidence of live attacks or remediation advice.

    1000065
    310 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Vendor. 0day Intel: 🌐 Cisco Unified Communications Alleged CVE-2026-20045 RCE Exploit Source Code A

    Post summary

    The tweet announces an alleged 0day CVE‑2026‑20045 in Cisco Unified Communications, mentioning the availability of exploit source code but providing no details, patches, or evidence of active usage.

    1000064
    310 followersView on X
  • Adam@seoscottsdale
    PoC

    4/8 Recent/2026 Supply Chain Examples: • Malicious PyPI dependencies dropping RATs (e.g., ChocoPoC via Mapbox abuse). • Cisco zero-day (CVE-2026-20045) in Unified Communications – impacts downstream voice/contact center services.  • GitHub Actions poisoning, typosquatting, and CDN hijacks (echoing http://Polyfill.io style). • Broader: MSP/software updates, open-source backdoors. 

    Post summary

    The note lists recent supply‑chain incidents, highlighting a PoC example in the form of "ChocoPoC" and a Cisco zero‑day CVE‑2026‑20045, but provides no active exploitation evidence, patch info, or detailed technical analysis.

    00010141
    12.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:03 UTC: Lyrie Sentinel flagged it. CVE-2026-20045 added to CISA KEV: Cisco Unified Communications Manager

    Post summary

    CVE-2026-20045 has been entered into the CISA Known Exploited Vulnerabilities list for Cisco Unified Communications Manager, indicating it is being actively exploited in the wild.

    1000057
    151 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:11 UTC: GPT-5 enrichment complete. 128 words. 3 citations. CVE-2026-20045 added to CISA KEV: Cisco Unified Communications Manager

    Post summary

    CVE-2026-20045 was added to the CISA KEV list for Cisco Unified Communications Manager, indicating the vulnerability is actively exploited in the wild, though no PoC, patch, or technical details are supplied.

    1000060
    151 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. CVE-2026-20045 added to CISA KEV: Cisco Unified Communications Manager

    Post summary

    The post announces the first in‑the‑wild exploit attempt against CVE‑2026‑20045, now listed in CISA KEV, indicating active exploitation.

    1000068
    151 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-20045 disclosed. CISA: CVE-2026-20045 added to Known Exploited Vulnerabilities — Cisco Unified Communications Manager CVE-2026-20045 added to CISA KEV: Cisco Unified Communications Manager

    Post summary

    CVE-2026-20045 has been disclosed and is now on the CISA Known Exploited Vulnerabilities list for Cisco Unified Communications Manager, indicating that active exploitation is occurring in the wild.

    1000068
    151 followersView on X
  • Telesmart Limited@Telesmartnz
    Patch

    [status] Scheduled (Feb 5, 2026, 22:00 NZDT): Scheduled - Webex Engineering has planned maintenance to install a COP file addressing CVE-2026-20045 in order to remediate defects CSCwr21851, CSCwr29216, and CSCwr29208. -- Scheduled Ma… https://stspg.io/gn3m81bg472f?u=0ns8w48vlxkc

    Post summary

    The status update announces scheduled maintenance to install a COP file that patches CVE-2026-20045, addressing several defects.

    1000058
    43 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/01/21:Cisco Unified CM の脆弱性 CVE-2026-20045 を登録 https://iototsecnews.jp/2026/01/22/cisco-unified-cm-zero-day-rce-under-attack-cisa-issues-warning/ Cisco Unified Communications Manager (Unified CM) の脆弱性 CVE-2026-20045 が CISA KEV カタログに登録されました。同庁は、この脆弱性の悪用が確認されたとして、連邦政府機関に対して緊急の対応を求めています。この問題の原因は、プログラムが外部からの入力を適切に処理できない、コード・インジェクションの欠陥に起因します。 細工したリクエストを送信するリモートの攻撃者は、低権限のユーザーとしてシステムに侵入し、そこから最高権限である root 権限へと昇格できてしまいます。これにより、通話内容やデータの窃取、さらにはネットワーク全体へのランサムウェア感染といった深刻な被害につながるリスクが生じます。ご利用のチームは、ご注意ください。 #CISA #Cisco #Exploit #Government #KEV #UnifiedCommunications #Vulnerability

    Post summary

    CISA KEV alert confirms CVE‑2026‑20045 is actively exploited via code injection, enabling remote privilege escalation to root, posing severe risks to Cisco Unified CM users.

    01000188
    485 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2026-20045-unified-communications-manager #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post announces that CVE‑2026‑20045 is actively exploited in the wild and implies the existence of a Proof of Concept, but offers no further exploitation details or patch information.

    0000028
    151 followersView on X
  • Komodo Cyber Security@Komodosec
    Active Exploitation

    #VulnerabilityReport #ActiveExploitation Under Attack: Critical Cisco RCE (CVE-2026-20045) Exploited in the Wild https://securityonline.info/under-attack-critical-cisco-rce-cve-2026-20045-exploited-in-the-wild/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces that CVE-2026-20045, a critical Cisco remote code execution vulnerability, is actively being exploited in the wild.

    0000073
    1.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscounified_communications_manager---
Appciscounified_communications_manager---
Appciscounified_communications_manager_im_and_presence_service---
Appciscounity_connection---

Explore more