A critical remote code execution (RCE) vulnerability has been identified in Cisco Unified Contact Center Express (CCX), tracked as CVE-2025-20354, with a CVSS score of 9.8. The flaw resides in the Java Remote Method Invocation (RMI) process and the CCX Editor, allowing unauthenticated attackers to upload arbitrary files and execute commands with root privileges on affected systems. The vulnerability is caused by improper authentication mechanisms associated with specific CCX features, making exploitation possible without prior access or credentials.
Successful exploitation enables remote attackers to gain full control over the underlying operating system, significantly increasing the risk of compromise for organizations using vulnerable Cisco CCX deployments. Cisco has acknowledged the issue and affected products, and organizations are urged to review their exposure and apply available mitigations or patches to prevent unauthorized root access and potential system takeover.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Alongside the advisory and patches, Cisco PSIRT stated it was not aware of in-the-wild exploitation of the UCCX vulnerabilities at the time of disclosure. Multiple reports repeated this assessment while urging organizations to patch quickly.
Cisco released security updates for Unified Contact Center Express to fix CVE-2025-20354 and CVE-2025-20358, two critical flaws that could let unauthenticated attackers bypass authentication and achieve high-privilege code execution. Fixed versions include v15.0 ES01 and v12.5 SU3 ES07, and Cisco said no workarounds are available.
Security researcher Jahmel Harris privately reported critical vulnerabilities affecting Cisco Unified Contact Center Express, including CVE-2025-20354 and CVE-2025-20358. The references do not specify the exact disclosure date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcethecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourcecsoonline.com
Open sourcecisecurity.org
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.