Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
Banner Ransomfeed 320x100 1
970x120 Olympous
Cisco Zero-Day Vulnerability CVE-2026-20045 Actively Exploited

Cisco Zero-Day Vulnerability CVE-2026-20045 Actively Exploited

22 January 2026 07:29

A critical zero-day remote code execution (RCE) vulnerability, identified as CVE-2026-20045, has been discovered by Cisco and is being actively exploited in active attacks. Cisco has urged immediate patching, and its Product Security Incident Response Team (PSIRT) has confirmed that attempts to exploit this vulnerability have occurred.

Cisco PSIRT has detected exploits targeting unpatched systems. Attackers are likely using automated scanners to identify exposed interfaces. Organizations using vulnerable VoIP/UC deployments must quickly update their infrastructure to avoid falling victim to attackers.

The bug affects major Unified Communications solutions and allows unauthenticated attackers to issue arbitrary commands on the underlying operating system, potentially gaining administrator privileges. This vulnerability affects the following Cisco products, regardless of device configuration:

No alternatives have been identified. In corporate VoIP configurations exposed through firewalls or VPNs, network access to the management interface is a requirement for exploitation, which is common.

The issue, Cisco reports in its advisory , stems from improper validation of user-supplied input in HTTP requests to the web-based management interface. An attacker sends forged HTTP requests that bypass authentication, execute user-level commands, and then elevate privileges to root. Cisco has classified the issue as Critical via the Security Impact Rating (SIR), ignoring the CVSS score due to the root-level risks.

Cisco has confirmed that this vulnerability does not affect the following Cisco products:

  • Contact Center SIP Proxy
  • Customer collaboration platform
  • emergency responder
  • Finesse
  • Packaged Contact Center Enterprise (Packaged CCE)
  • Prime Collaboration Distribution
  • Unified Enterprise Contact Center (Unified EHR)
  • Unified Contact Center Express (Unified CCX)
  • Unified Intelligence Center (CUIC)
  • Virtualized Voice Browser

CISA soon added this vulnerability to the known exploited vulnerabilities.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.