CVE-2026-20045: Cisco Unified Communications Manager
EPSS4.5%No. 1435 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV100
Same product2
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | Unified Communications Manager |
| Name | Cisco Unified Communications Products Code Injection Vulnerability |
| Added to KEV | 2026-01-21 |
| US federal due date | 2026-02-11 |
| Ransomware use | Unknown |
| CWE | CWE-94 |
CISA description
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-20230 | Cisco Unified Communications Manager | 2026-06-25 | 88.2% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco Unified Communications Manager vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-21.