Cisco IP Phones Hit by High-Severity Denial-of-Service Vulnerability (CVE-2026-20281)
Cisco has disclosed a high-severity vulnerability affecting a range of its IP and video phones that could allow an unauthenticated remote attacker to cause the devices to become unavailable.
Tracked as CVE-2026-20281, the vulnerability carries a CVSS score of 7.5 out of 10 and has been classified as a high-severity denial-of-service flaw. Cisco says the issue is caused by improper memory management when affected devices process HTTP packets.
An attacker could exploit the vulnerability by sending a continuous stream of specially crafted HTTP packets to a vulnerable phone. If successful, the device could continuously consume memory until it enters a denial-of-service condition.
Cisco says a manual reboot is required to recover an affected device.
Which devices are affected?
CVE-2026-20281 affects Cisco devices running its Session Initiation Protocol (SIP) software, including:
- Cisco Desk Phone 9800 Series
- Cisco IP Phone 7800 Series
- Cisco IP Phone 8800 Series
- Cisco Video Phone 8875
- Cisco IP Phone 8845 and 8865
- Cisco Wireless IP Phone 8821
However, the vulnerability is subject to an important condition. For the attack to work, the phone must be registered with Cisco Unified Communications Manager (Unified CM) and Web Access must be enabled. Cisco notes that Web Access is disabled by default.
Updates available
Cisco has released software updates addressing the vulnerability and says there are no workarounds available. Customers are advised to upgrade to the appropriate fixed release rather than relying on temporary mitigations.
For example, Cisco identifies 14.4(1)SR3 as a fixed release for some affected 9800/7800/8800 models, while the 8845 and 8865 are fixed in 14.4(1)SR4. The Wireless IP Phone 8821 is fixed in 11.0(6)SR8.
Cisco’s Product Security Incident Response Team says it is not aware of public exploitation or malicious use of CVE-2026-20281 at this time. The vulnerability was reported by security researcher Bertie Hallows.
What organisations should do
Organisations using affected Cisco phones should check their SIP software versions and configuration, particularly whether Web Access has been enabled. Although exploitation requires a specific configuration, the ability to remotely exhaust memory and force phones offline could cause disruption to business communications.
Cisco recommends installing the relevant security update as soon as practical.
CVE-2026-20281 at a glance
| Detail | Information |
|---|---|
| Vendor | Cisco |
| CVE | CVE-2026-20281 |
| Severity | High |
| CVSS | 7.5 |
| Type | Denial of Service |
| CWE | CWE-401 – Improper Release of Memory Before Removing Last Reference |
| Attack | Remote, unauthenticated |
| User interaction | None |
| Exploitation known? | No known malicious exploitation |
| Workaround | None |
| Fix available | Yes |
Cisco published the advisory on 2 September 2026

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
