Source record · tier 2 current vendor documentation
Cisco Unified Communications Products Remote Code Execution Vulnerability
- Publisher
- Cisco PSIRT
- URL
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b
- Published
- 2026-02-13
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- Cisco website terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- Because Release 12.5 is past end of support and CVE-2026-20045 has no 12.5 fix, a 12.5 cluster can only remediate it by upgrading to 14SU5, 15SU4 or later; the supported direct path is a direct standard upgrade to Release 15. inferred in context
- CVE-2026-20045 (cisco-sa-voice-rce-mORhqY4b) is a Critical-rated vulnerability, CVSS base 8.2, in the web management interface of Unified CM, SME, IM and Presence, Unity Connection and Webex Calling Dedicated Instance. An unauthenticated attacker can gain OS access and escalate to root. in context
- CVE-2026-20045 is fixed in Unified CM 14SU5 and 15SU4, or by the patch ciscocm.CSCwr21851_Remote_Code_Execution_v1; Release 12.5 customers must migrate to a fixed release. in context
- CVE-2026-20045 has no workarounds, and Cisco PSIRT reports attempted exploitation in the wild. in context
Cite this source record
APA
WarmTransfer. (2026, February 13). Cisco Unified Communications Products Remote Code Execution Vulnerability. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-sa-voice-rce-morhqy4b
BibTeX
@misc{warmtransfer-cisco-sa-voice-rce-morhqy4b,
title = {Cisco Unified Communications Products Remote Code Execution Vulnerability},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-sa-voice-rce-morhqy4b},
note = {Cisco PSIRT, accessed 2026-09-30}
}