NewsSecurity Vulnerabilities

Cisco IP Phones Hit by High-Severity Denial-of-Service Vulnerability (CVE-2026-20281)

Cisco has disclosed a high-severity vulnerability affecting a range of its IP and video phones that could allow an unauthenticated remote attacker to cause the devices to become unavailable.

Tracked as CVE-2026-20281, the vulnerability carries a CVSS score of 7.5 out of 10 and has been classified as a high-severity denial-of-service flaw. Cisco says the issue is caused by improper memory management when affected devices process HTTP packets.

An attacker could exploit the vulnerability by sending a continuous stream of specially crafted HTTP packets to a vulnerable phone. If successful, the device could continuously consume memory until it enters a denial-of-service condition.

Cisco says a manual reboot is required to recover an affected device.

Which devices are affected?

CVE-2026-20281 affects Cisco devices running its Session Initiation Protocol (SIP) software, including:

  • Cisco Desk Phone 9800 Series
  • Cisco IP Phone 7800 Series
  • Cisco IP Phone 8800 Series
  • Cisco Video Phone 8875
  • Cisco IP Phone 8845 and 8865
  • Cisco Wireless IP Phone 8821

However, the vulnerability is subject to an important condition. For the attack to work, the phone must be registered with Cisco Unified Communications Manager (Unified CM) and Web Access must be enabled. Cisco notes that Web Access is disabled by default.

Updates available

Cisco has released software updates addressing the vulnerability and says there are no workarounds available. Customers are advised to upgrade to the appropriate fixed release rather than relying on temporary mitigations.

For example, Cisco identifies 14.4(1)SR3 as a fixed release for some affected 9800/7800/8800 models, while the 8845 and 8865 are fixed in 14.4(1)SR4. The Wireless IP Phone 8821 is fixed in 11.0(6)SR8.

Cisco’s Product Security Incident Response Team says it is not aware of public exploitation or malicious use of CVE-2026-20281 at this time. The vulnerability was reported by security researcher Bertie Hallows.

What organisations should do

Organisations using affected Cisco phones should check their SIP software versions and configuration, particularly whether Web Access has been enabled. Although exploitation requires a specific configuration, the ability to remotely exhaust memory and force phones offline could cause disruption to business communications.

Cisco recommends installing the relevant security update as soon as practical.

CVE-2026-20281 at a glance

DetailInformation
VendorCisco
CVECVE-2026-20281
SeverityHigh
CVSS7.5
TypeDenial of Service
CWECWE-401 – Improper Release of Memory Before Removing Last Reference
AttackRemote, unauthenticated
User interactionNone
Exploitation known?No known malicious exploitation
WorkaroundNone
Fix availableYes

Cisco published the advisory on 2 September 2026

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.