CVE-2026-20059
CVSS 6.1 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
Vulnerabilità · 167 giorni fa
Cisco Unity Connection’s web management interface can be abused to run script in an admin’s browser or send users to a malicious site. The standard response is to treat this as a low-grade web bug, but on a management plane that handles voice infrastructure, browser compromise can expose privileged sessions and internal admin workflows.
Cisco says CVE-2026-20059 is a reflected XSS flaw and CVE-2026-20060 is an open redirect flaw. Both affect Cisco Unity Connection and are fixed in vendor software updates; Cisco says there are no workarounds.
The immediate risk is not service outage. It is that an attacker can turn a trusted admin link into a session-theft or lure path against the people who manage the system.
CVSS 6.1 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
CVSS 4.7 MEDIUM: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated…
3 fonti che coprono questa storia
Cisco Security Advisory: Cisco Webex Services Certificate Validation Vulnerability
Cisco has addressed this vulnerability in the Cisco Webex service.
Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code Execution
Cisco patches four CVEs up to CVSS 9.9 in ISE and Webex, preventing code execution and user impersonation risks.
Cisco Patches Critical Vulnerabilities in Webex, ISE
The flaws can be exploited remotely to impersonate users or execute arbitrary commands on the underlying OS.
Cisco has released software updates that address these vulnerabilities.
Cisco has released software updates that address these vulnerabilities.
Cisco Security Advisory: Cisco Identity Services Engine Remote Code Execution Vulnerabilities
Cisco has released software updates that address these vulnerabilities.
Cisco Security Advisory: Cisco Unity Connection Arbitrary File Download Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system.
Cisco has released software updates that address this vulnerability.
Cisco Security Advisory: Cisco Webex Contact Center Cross-Site Scripting Vulnerability
Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is needed.
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to conduct a cross-site scripting (XSS) attack, an open redirect attack, and an SQL injection attack.
Part of the PlainSec briefing for 2026-04-16