Spark Professional Services’ Offensive Security Team has identified and responsibly disclosed three vulnerabilities affecting components of the Cisco Unified Contact Center stack, with the findings now reflected in published Cisco security advisories. The vulnerabilities include CVE-2026-20109, a Cross-Site Scripting (XSS) vulnerability affecting Cisco Unified CCE and Packaged CCE; CVE-2026-20327, a SQL Injection vulnerability in Cisco Unified Intelligence Center; and CVE-2026-20314, a Server-Side Request Forgery (SSRF) vulnerability affecting Cisco Unified CCE and Packaged CCE.
The research demonstrates the team’s continued focus on identifying vulnerabilities within enterprise technologies and understanding how they could present risks in real-world environments. By examining the Cisco Unified Contact Center stack from an offensive security perspective, the team uncovered multiple classes of vulnerabilities spanning web application security, database interactions, and server-side request handling, highlighting the importance of testing complex enterprise systems beyond their intended functionality.
The vulnerabilities were responsibly disclosed to Cisco, with the Cisco security team collaborating throughout the disclosure and remediation process. The publication of the three advisories marks another example of coordinated efforts between security researchers and technology vendors to identify, address, and reduce potential risks before they can be exploited in the wild.
The findings also reflect a broader approach to offensive security at Spark Professional Services, where vulnerability research goes beyond identifying isolated technical weaknesses to understanding potential attack paths and the ways vulnerabilities can affect enterprise environments. This approach enables security teams to gain a clearer picture of their exposure and take more informed steps to strengthen their systems and reduce risk.
Spark Professional Services’ Offensive Security Team continues to contribute to the cybersecurity ecosystem through security research and responsible disclosure, with a focus on helping organizations better understand emerging threats and build more resilient systems. Through this work, the company positions offensive security not simply as a process of finding vulnerabilities, but as a practical discipline for understanding how real attacks can occur and helping enterprises prepare for them.





