Critical vulnerability in Cisco products: risk of remote control on communication systems

In the cybersecurity landscape, vulnerabilities in communication systems represent a particularly serious threat for organizations. A recent case involved Cisco, one of the world’s leading providers of network and communication technologies, with the discovery of a critical flaw that required urgent intervention.

On January 21, 2026, Cisco released an emergency patch to fix vulnerability CVE-2026-20045, a critical defect affecting various Cisco Unified Communications products, including Unified CM, Session Management Edition, IM & Presence Service, Unity Connection, and Webex Calling Dedicated Instance. The vulnerability allows malicious actors to execute arbitrary code on vulnerable systems without authentication, simply by sending specially crafted HTTP requests to the web management interface. What makes the situation particularly serious is that this vulnerability was already being actively exploited before the fix was released.

The potential impact of this vulnerability is extremely significant. Attackers could potentially obtain administrator (root) privileges on compromised systems, allowing them to take complete control of the communication infrastructure. With approximately 1,300 Cisco Unified CM instances exposed on the Internet, nearly half of which are in the United States, the scope of the risk is considerable. CISA (Cybersecurity and Infrastructure Security Agency) has added this vulnerability to the “Known Exploited Vulnerabilities” catalog, requiring U.S. federal agencies to apply the patch by February 11, 2026.

For companies using the affected Cisco products, the only available solution is to immediately apply the security updates released by the manufacturer. There are no alternative measures (workarounds) to mitigate the risk without installing the patches. Organizations should also carefully monitor their systems to identify any signs of compromise and, when in doubt, consult their cybersecurity team or an external expert.

  • Key points to remember:
  • Vulnerability CVE-2026-20045 affects Cisco Unified Communications products and allows remote code execution without authentication
  • Approximately 1,300 vulnerable systems are exposed on the Internet, making the application of security patches urgent
  • The only solution is immediate system updating, as there are no alternative measures to protect yourself

Sources:
https://codekeeper.co/ticker/cisco-zero-day-flaw-unified-communications
https://www.theregister.com/2026/01/22/another_week_another_emergency_patch/
https://thehackernews.com/2026/01/cisco-fixes-actively-exploited-zero-day.html
https://socprime.com/blog/cve-2026-20045-vulnerability/
https://www.securityweek.com/hackers-targeting-cisco-unified-cm-zero-day/
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b

Source: Dark Reading