Cisco Unity Connection Bugs Expose Admin Web Sessions

Cisco Unity Connection’s web management interface can be abused to run script in an admin’s browser or send users to a malicious site. The standard response is to treat this as a low-grade web bug, but on a management plane that handles voice infrastructure, browser compromise can expose privileged sessions and internal admin workflows. Cisco says CVE-2026-20059 is a reflected XSS flaw and CVE-2026-20060 is an open redirect flaw. Both affect Cisco Unity Connection and are fixed in vendor software updates; Cisco says there are no workarounds. The immediate risk is not service outage. It is that an attacker can turn a trusted admin link into a session-theft or lure path against the people who manage the system.

Part of the PlainSec briefing for 2026-04-16

Editions

Sources