Skip to content
VulniPulse
Highest advisory severityHigh Exploited CISA KEV 1 vendor · 1 advisory

CVE-2026-20045

CVE-2026-20045: 1 tracked advisory record across Cisco. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityHigh8.2

    High [CVE-2026-20045] Cisco Unified Communications Products Remote Code Execution Vulnerability

    cisco-sa-voice-rce-mORhqY4bSource published Source updated

    A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of craf…

    Related products — impact not confirmed
    • Cisco Unity Connection
    • Cisco Unified Communications Manager IM and Presence Service
    • Webex
    Source-reported affected versions
    • Scope: This vulnerability affects the following Cisco products, regardless of device configuration:
    • 12.5 — Migrate to a fixed release
    • Release 14 (first fixed: 14SU5 or apply patch file:1)
    • Release ciscocm.CSCwr21851_Remote_Code_Execution_v1.zip (first fixed: 15)

    5 more entries in the full advisory.

    Source-reported fixed versions
    • 14SU5 or apply patch file:1
    • 15
    • ciscocm.CSCwr21851_Remote_Code_Execution_v1.zip
    • ciscocm.cuc.CSCwr29208_C0266-v2.zip
    Mitigation guidance
    • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
    • Release 12.5: migrate to a fixed release.
    • Release 14: upgrade to 14SU5 or apply patch file:1.
    • Release ciscocm.CSCwr21851_Remote_Code_Execution_v1.zip: upgrade to 15.

    5 more entries in the full advisory.

    Workarounds
    • There are no workarounds that address this vulnerability.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery