Cisco warns of critical Unified Communications flaw with no workaround; patches urged
Cisco issued a critical security advisory for CVE-2026-20045, an unauthenticated remote code execution vulnerability affecting Unified Communications products including Unified CM, Unity Connection, and Webex Calling Dedicated Instance, urging customers to apply updates because no workaround exists.
- PUBLISHED
- UPDATED

Cisco on January 21, 2026 published a critical security advisory for a remote code execution vulnerability affecting multiple Unified Communications products used widely in enterprise voice and collaboration environments. The flaw, tracked as CVE-2026-20045, carries heightened urgency because it can be exploited remotely without authentication and could ultimately lead to root-level compromise.

Cisco said the affected products include Unified Communications Manager (Unified CM), Unified CM Session Management Edition (SME), Unified CM IM & Presence Service (IM&P), Unity Connection, and Webex Calling Dedicated Instance. The vulnerability stems from improper validation of user-supplied input in HTTP requests to a web-based management interface.
In its advisory, Cisco explained that a successful attacker could execute arbitrary commands on the underlying operating system of an affected device. The company said an attacker could exploit the issue by sending a sequence of crafted HTTP requests, potentially gaining user-level access and then escalating privileges to root.
Cisco emphasized that there are no workarounds that address the vulnerability and that customers should apply software updates that remediate the issue. For organizations that run voice systems tightly integrated into business operations—call routing, voicemail, conferencing, and presence—patching can be operationally sensitive, but the risk profile is high because these servers are often connected to large internal networks.
Security teams commonly treat collaboration infrastructure as “always on,” which can lead to delayed maintenance windows. The advisory reinforces why organizations should inventory exposed management interfaces, restrict administrative access where possible, and prioritize remediation for systems accessible from untrusted networks.
The disclosure also lands during a period of heightened attention to enterprise patch management, as major vendors and researchers continue to report active exploitation of high-impact vulnerabilities shortly after disclosure. In this environment, defenders are urged to act quickly: patch, verify versions, monitor logs for unusual web-interface traffic, and ensure incident response playbooks cover core communications systems—not only endpoints and email.