Exploited Vulnerabilities Daily
🌐 English

Home › Cisco

CVE-2026-20045: Cisco Unified Communications Manager

EPSS4.5%No. 1435 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV100
Same product2
FieldValue
VendorCisco
ProductUnified Communications Manager
NameCisco Unified Communications Products Code Injection Vulnerability
Added to KEV2026-01-21
US federal due date2026-02-11
Ransomware useUnknown
CWECWE-94

CISA description

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-20230Cisco Unified Communications Manager2026-06-2588.2%Unknown

NVD — CVE-2026-20045

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Cisco Unified Communications Manager vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-21.