Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cisco fixes actively exploited zero-day CVE-2026-20045 in Unified CM and Webex
Identity

Cisco fixes actively exploited zero-day CVE-2026-20045 in Unified CM and Webex

userBy userJanuary 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananJanuary 22, 2026Vulnerability/Zero-day

Cisco has released a new patch to address what it describes as a “critical” security vulnerability affecting multiple unified communications (CM) products and Webex Calling dedicated instances. This vulnerability is actively being exploited in the wild as a zero-day attack.

Vulnerability CVE-2026-20045 (CVSS score: 8.2) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.

“This vulnerability is due to improper validation of user-supplied input in an HTTP request,” Cisco said in an advisory. “An attacker could exploit this vulnerability by sending a series of crafted HTTP requests to the web-based management interface of an affected device. Successful exploitation could allow the attacker to gain user-level access to the underlying operating system and escalate privileges to root.”

cyber security

It added that the serious rating given to this flaw is due to the fact that, if exploited, this flaw could allow privilege escalation to root. This vulnerability affects the following products:

Unified CM Unified CM Session Management Edition (SME) Unified CM IM & Presence Service (IM&P) Unity Connection Webex Calling dedicated instance

This issue has been resolved in the following versions:

Cisco Unified CM, CM SME, CM IM&P, and Webex Calling dedicated instances –

Release 12.5 – Fixed Release Migrate to Release 14 – 14SU5 or apply the patch file: ciscocm.V14SU4a_CSCwr21851_remote_code_v1.cop.sha512 Release 15 – 15SU4 (March 2026) or apply the patch file: ciscocm.V15SU2_CSCwr21851_remote_code_v1.cop.sha512 or ciscocm.V15SU3_CSCwr21851_remote_code_v1.cop.sha512

Cisco Unity Connection

Release 12.5 – Fixed Release Migrate to Release 14 – 14SU5 or apply the patch file: ciscocm.cuc.CSCwr29208_C0266-1.cop.sha512 Release 15 – 15SU4 (March 2026) or apply the patch file: ciscocm.cuc.CSCwr29208_C0266-1.cop.sha512

cyber security

The networking equipment giant also said it was “aware of attempts to exploit this vulnerability in the wild” and urged customers to upgrade to a fixed software release that addresses the issue. There is currently no workaround. An anonymous external researcher is said to have discovered and reported this bug.

Due to this development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20045 to its Known Exploited Vulnerabilities (KEV) Catalog and requires Federal Civilian Executive Branch (FCEB) agencies to apply a fix by February 11, 2026.

The discovery of CVE-2026-20045 comes less than a week after Cisco released an update for another actively exploited critical security vulnerability (CVE-2025-20393, CVSS score: 10.0) affecting AsyncOS software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This vulnerability could allow an attacker to execute arbitrary commands with root privileges.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSource: Project SGLang spun out as RadixArk valued at $400 million as inference market explodes
Next Article Automated FortiGate attack exploits FortiCloud SSO to change firewall configuration
user
  • Website

Related Posts

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026

Experts detect Pakistan-linked cyber attack targeting Indian government agencies

January 27, 2026

ClickFix attack spreads using fake CAPTCHAs, Microsoft Scripts, and trusted web services

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Amid President Trump’s attacks and weaponized sanctions, European countries seek to reduce dependence on U.S. technology

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.