Cisco has disclosed critical vulnerabilities in Unified Contact Center Express ( CCX) that could allow unauthenticated remote attackers to execute malicious code and gain elevated privileges on vulnerable systems .

The vulnerabilities affect the Java Remote Method Invocation (RMI) process and authentication mechanisms , potentially putting entire contact center deployments at risk.
See also: Multiple vulnerabilities in Django allow SQL Injection and DoS
Cisco Unified Contact Center Express: Critical Vulnerabilities
The primary vulnerability, CVE-2025-20354, has a CVSS score of 9.8/10 and allows attackers to upload arbitrary files via the Java RMI process without authentication. Successful exploitation allows attackers to execute commands with root privileges on affected systems.
The vulnerability arises from improper authentication mechanisms in Cisco Unified CCX, leaving organizations' contact center infrastructure exposed to full compromise. Attackers could exploit this weakness for persistent access, to steal sensitive customer data, or to deploy ransomware to entire contact center networks.
See also: Cisco: Hackers exploit ASA and FTD vulnerability

CVE -2025-20358 is also a critical authentication bypass affecting the CCX Editor application. Rated 9.4 on the CVSS scale, this vulnerability allows attackers to redirect the authentication flow to malicious servers, tricking the CCX Editor into believing that legitimate authentication has occurred.
Once bypassed, attackers gain administrative privileges to create and execute arbitrary scripts as internal non-root users. This combination of vulnerabilities creates a complex attack chain that allows remote attackers to escalate privileges and maintain control over the contact center operations.
See also: AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

Protection
Cisco has released software updates that address both vulnerabilities, with no workarounds available. Organizations using Unified CCX version 12.5 SU3 and earlier should immediately upgrade to version 12.5 SU3 ES07 . Users on version 15.0 should install version 15.0 ES01 . The vulnerabilities affect all Unified CCX configurations regardless of deployment settings.
Other Cisco products, including Unified Contact Center Enterprise (CCE) and Packaged Contact Center Enterprise, remain unaffected.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
