Vulnerabilities & Exploits
Cisco Unity Connection Bugs Expose Admin Web Sessions Cisco Unity Connection’s web management interface can be abused to run script in an admin’s browser or send users to a malicious site. The standard response is to treat this as a low-grade web bug, but on a management plane that handles voice infrastructure, browser compromise can expose privileged sessions and internal admin workflows.
Cisco says CVE-2026-20059 is a reflected XSS flaw and CVE-2026-20060 is an open redirect flaw. Both affect Cisco Unity Connection and are fixed in vendor software updates; Cisco says there are no workarounds.
The immediate risk is not service outage. It is that an attacker can turn a trusted admin link into a session-theft or lure path against the people who manage the system.
3 sources · Apr 16
CVE-2026-20059 NVD KEV
CVSS 6.1 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
CVE-2026-20060 NVD KEV
CVSS 4.7 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
Timeline Sources Apr 16 Cisco PSIRT
Cisco Security Advisory: Cisco Webex Services Certificate Validation Vulnerability
Cisco has addressed this vulnerability in the Cisco Webex service.
original Apr 16 The Hacker News
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
Cisco patches four CVEs up to CVSS 9.9 in ISE and Webex, preventing code execution and user impersonation risks.
original Apr 16 SecurityWeek
Cisco Patches Critical Vulnerabilities in Webex, ISE
The flaws can be exploited remotely to impersonate users or execute arbitrary commands on the underlying OS.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-04-16
Every edition of this story: Cisco Unity Connection Bugs Expose Admin Web Sessions
More from today
Vulnerabilities & Exploits
Cisco Unity Connection Bugs Expose Admin Web Sessions Cisco Unity Connection’s web management interface can be abused to run script in an admin’s browser or send users to a malicious site. The standard response is to treat this as a low-grade web bug, but on a management plane that handles voice infrastructure, browser compromise can expose privileged sessions and internal admin workflows.
Cisco says CVE-2026-20059 is a reflected XSS flaw and CVE-2026-20060 is an open redirect flaw. Both affect Cisco Unity Connection and are fixed in vendor software updates; Cisco says there are no workarounds.
The immediate risk is not service outage. It is that an attacker can turn a trusted admin link into a session-theft or lure path against the people who manage the system.
3 sources · Apr 16
CVE-2026-20059 NVD KEV
CVSS 6.1 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
CVE-2026-20060 NVD KEV
CVSS 4.7 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
Timeline Sources Apr 16 Cisco PSIRT
Cisco Security Advisory: Cisco Webex Services Certificate Validation Vulnerability
Cisco has addressed this vulnerability in the Cisco Webex service.
original Apr 16 The Hacker News
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
Cisco patches four CVEs up to CVSS 9.9 in ISE and Webex, preventing code execution and user impersonation risks.
original Apr 16 SecurityWeek
Cisco Patches Critical Vulnerabilities in Webex, ISE
The flaws can be exploited remotely to impersonate users or execute arbitrary commands on the underlying OS.
original Vendor digest: Cisco
Part of the PlainSec briefing for 2026-04-16
Every edition of this story: Cisco Unity Connection Bugs Expose Admin Web Sessions
More from today