CISCO Security Advisory

Published Date: June 22, 2026

CVE: CVE-2026-20055

Advisory Summary

⚠️ Security Alert: Cross-Site Scripting

Cisco has identified multiple cross-site scripting (XSS) vulnerabilities in the web-based management interfaces of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE). These flaws arise due to improper validation of user-supplied input, enabling a remote, authenticated attacker with administrative credentials to inject malicious scripts. Successful exploitation could result in unauthorized script execution or access to sensitive browser data within the management interface context.

Immediate action is recommended to apply the latest patches to mitigate potential attack vectors affecting contact center infrastructure, preserving both security and operational continuity.

Reference: Vendor Advisory