Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands

Multiple vulnerabilities in Cisco Unified CCX Allow Attackers to Execute Arbitrary Commands

Posted on November 14, 2025November 14, 2025 By CWS

Cisco has launched safety updates to handle two vital vulnerabilities in Unified Contact Heart Specific (Unified CCX) that would enable unauthenticated attackers to execute arbitrary instructions with root privileges and bypass authentication mechanisms.

The failings, tracked as CVE-2025-20354 and CVE-2025-20358, have an effect on the Java Distant Technique Invocation (RMI) course of and CCX Editor utility, respectively.

Each vulnerabilities stem from improper authentication mechanisms and carry CVSS base scores of 9.8 and 9.4, incomes a “Important” severity ranking from Cisco.

CVE-2025-20354 represents the extra extreme menace, enabling distant attackers to add malicious information by way of the Java RMI course of with out authentication.

Profitable exploitation permits attackers to execute arbitrary instructions on the underlying working system with root privileges, granting full system management.

CVE-2025-20358 targets the CCX Editor utility, permitting attackers to avoid authentication by redirecting the authentication movement to a malicious server.

This methods the CCX Editor into granting administrative permissions for script creation and execution. Whereas exploitation leads to entry as an inside non-root consumer reasonably than root, attackers can nonetheless create and execute arbitrary scripts on the affected server.

Cisco Unified CCX Vulnerability

The vulnerabilities have an effect on all Cisco Unified CCX deployments no matter configuration. Cisco has confirmed that associated merchandise, together with Packaged Contact Heart Enterprise and Unified Contact Heart Enterprise, will not be impacted by these flaws.

The authentication bypass in CVE-2025-20358 exploits weaknesses in communication protocols between the CCX Editor and Unified CCX servers, whereas CVE-2025-20354 leverages inadequate validation within the Java RMI course of to allow arbitrary file uploads.

Cisco has launched patches for affected variations:

Cisco Unified CCX 12.5 SU3 and earlier: Improve to 12.5 SU3 ES07

Cisco Unified CCX 15.0: Improve to fifteen.0 ES01

No workarounds can be found to mitigate these vulnerabilities. Cisco strongly recommends that organizations operating affected variations improve to the fastened releases instantly to remediate the safety dangers totally.

Organizations utilizing Cisco Unified CCX ought to prioritize patching these vulnerabilities given their vital severity and the potential for unauthenticated distant code execution.

The Cisco Product Safety Incident Response Workforce studies no proof of lively exploitation or public proof-of-concept code right now, offering a window for proactive remediation.

System directors ought to confirm their present Unified CCX variations and schedule upkeep home windows to use the safety updates. Given the dearth of workarounds, patching stays the one efficient protection in opposition to these vulnerabilities.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Arbitrary, Attackers, CCX, Cisco, Commands, Execute, Multiple, Unified, Vulnerabilities

Post navigation

Previous Post: Hackers Flooded npm Registry Over 43,000 Spam Packages Survived for Almost Two Years
Next Post: Akira Ransomware Group Made $244 Million in Ransom Proceeds

Related Posts

Hackers Delivering Cobalt Strike Beacon Leveraging GitHub and Social Media Hackers Delivering Cobalt Strike Beacon Leveraging GitHub and Social Media Cyber Security News
Threat Actors Compromise 270+ Legitimate Websites With Malicious JavaScript Using JSFireTruck Obfuscation Threat Actors Compromise 270+ Legitimate Websites With Malicious JavaScript Using JSFireTruck Obfuscation Cyber Security News
How to Conduct a Secure Code Review How to Conduct a Secure Code Review Cyber Security News
Horabot Trojan Targets Mexico with Phishing Campaign Horabot Trojan Targets Mexico with Phishing Campaign Cyber Security News
Phishing Scam Targets Booking.com Users in Fraud Scheme Phishing Scam Targets Booking.com Users in Fraud Scheme Cyber Security News
Enhancing Early Threat Detection in SOCs with Limited Staff Enhancing Early Threat Detection in SOCs with Limited Staff Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark