Fix out for remotely exploited Cisco enterprise UC suite bug

By
Follow google news

Flaw allows for RCE and root privilege escalation.

Patches are available for a critical vulnerability in Cisco's unified communications (UC) products, following detection of the bug being exploited by attackers in the wild.

Fix out for remotely exploited Cisco enterprise UC suite bug

Unauthenticated remote attackers can execute arbitrary code on the underlying operating system of the UC products, via their web-based management interface.

A successful exploit could allow the attacker to obtain user-level access to the operating system on unpatched devices, and then escalate their privileges to those of the root super-user with full administrative rights.

Improper validation of user-supplied HTTP requests, which attackers can abuse, is behind the remote code execution vulnerability.

Cisco's Unified Communications Manager (CM), CM SME, CM IM&P, Unity Connection and Webex Dedicated Calling Instance are affected and need to be patched.

There are no workarounds for the flaw which is scored as 8.2 out of 10.

The United States Cybersecurity and Infrastructure Agency (CISA) has added the flaw, tracked as CVE-2026-20045, to its Known Exploited Vulnerabilities must-fix catalogue.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia to tap law enforcement data for staff security

Services Australia to tap law enforcement data for staff security

Vic Education database breached via school's network

Vic Education database breached via school's network

Microsoft patches single-click Copilot data stealing attack

Microsoft patches single-click Copilot data stealing attack

Microsoft releases fix for flawed January security update

Microsoft releases fix for flawed January security update

Log In

  |  Forgot your password?