Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2721 articles · 132331 vulns · 35/41 feeds (7d)
← Back to list
8.8
CVE-2026-20034
Cisco · Cisco Unity Connection

Cisco Unity Connection Remote Code Execution Vulnerability

Description

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of a targeted device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

Affected Products

VendorProductVersions
CiscoCisco Unity Connection12.5(1), 12.5(1)SU1, 12.5(1)SU2, 12.5(1)SU3, 12.5(1)SU4, 14, 12.5(1)SU5, 14SU1, 12.5(1)SU6, 14SU2, 12.5(1)SU7, 14SU3, 12.5(1)SU8, 14SU3a, 12.5(1)SU8a, 15, 15SU1, 14SU4, 12.5(1)SU9, 15SU2, 15SU3

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy

Related News (1 articles)

Tier C
VulDB7h ago
CVE-2026-20034 | Cisco Unity Connection up to 15SU3 API path traversal (cisco-sa-unity-rce-ssrf-hENhuASy)
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-35
PublishedMay 6, 2026
Last enriched7h ago
Trending Score31
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20188
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Connection Exhaustion Denial of Service Vulnerability
Trending: 47
HIGHCVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Trending: 26
HIGHCVE-2026-20185
Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability
Trending: 26
HIGHCVE-2026-20035
Cisco Unity Connection Server-Side Request Forgery Vulnerability
Trending: 26
MEDIUMCVE-2026-20168
Cisco IoT Field Network Director Path Traversal Vulnerability
Trending: 23

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026