Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition. Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv Security Impact Rating: High CVE: CVE-2026-20281
CSIRTS triage
- What
- Improper memory management when processing HTTP packets leads to continuous memory consumption causing denial of service.
- Who is affected
- Cisco desk and IP phones running SIP Software with Web Access enabled and registered to Unified CM.
- Urgency
- High; easily triggered by continuous HTTP packets and requires manual reboot to recover.
- Action
- Apply software patches and disable Web Access if not required, or restrict HTTP access to trusted networks.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, Video Phone 8875 SIP Software
Get an email when a new Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, Video Phone 8875 SIP Software advisory drops — max one per day, one-click unsubscribe.
Details
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20281 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Cisco IP Phone: Vulnerability enables Denial of Servicecert-bund
- highCVE-2026-20281: A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisc…nvd
- criticalCisco Advance Notification for Publication of September 2, 2026, Security Advisoriescisco-psirt
More from Cisco Security Advisories
- criticalCisco IOS XR Software Security Hardening Release: September 20262026-09-02
- criticalCisco Advance Notification for Publication of September 2, 2026, Security Advisories2026-09-02
- criticalCisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability2026-09-02
- mediumCisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities2026-09-02
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21