Group-IB Red Team discovers zero-day vulnerabilities in Cisco UCCX and IBM Sterling

Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, today announced the discovery of two previously unknown zero-day vulnerabilities in widely used enterprise products: Cisco Unified Contact Center Express (UCCX) and IBM Sterling. The vulnerabilities were identified by Group-IB’s adversary-centric intelligence during a client assessment, demonstrating the depth of the company’s proactive defense threat-intelligence-driven cybersecurity capabilities and its ongoing commitment to responsible research.

While many security assessments focus on identifying known CVEs (common vulnerabilities and exposures) and publicly documented weaknesses, Group-IB’s Red Team follows the same methodology as real-world adversaries, leveraging deep empirical threat intelligence to replicate highly advanced attacks. This approach involves examining software at the architectural and code level with the precision required to uncover never-before-seen vulnerabilities, a level of analysis critical to understanding how sophisticated threat actors infiltrate enterprise environments.

Cisco Unified Contact Center Express (UCCX) is Cisco’s widely used platform for managing enterprise contact centers, providing automated call distribution, interactive voice response (IVR), and customer-service workflows for organizations across banking, telecommunications, government, and other sectors. IBM Sterling is a suite of supply-chain and B2B integration solutions used by enterprises globally to support secure data exchange, logistics, operations, order management, and partner connectivity.

The discovered vulnerabilities include:

Both vulnerabilities were responsibly disclosed to Cisco and IBM by Group-IB’s researchers. After reviewing the reports, both vendors confirmed the issues and released security patches to protect their customers.

“Enterprise software often contains zero-day vulnerabilities and deep-seated misconfigurations, particularly in systems deployed far within corporate infrastructures or in products that researchers have limited access to. Unfortunately, many of these vulnerabilities don’t receive a CVE (Common Vulnerabilities and Exposures) identifier due to inconsistent disclosure practices – including cases where vendors silently patch flaws. This lack of transparency can ultimately weaken the security posture of those organizations’ customers and the wider ecosystem. Group-IB thanks Cisco and IBM for their collaboration and commends their exemplary and responsible engagement by working with our team to ensure full and transparent CVE publication.”

Konstantin Damotsev

Global Head of Red Teaming Practice, Group-IB

Zero-day vulnerabilities remain one of the most valuable tools for advanced cybercriminals and nation-state threat actors. By identifying and reporting them responsibly, Group-IB helps reduce systemic risk across critical industries that rely on platforms like Cisco UCCX and IBM Sterling for communications, logistics, and operational continuity.

Group-IB maintains highly specialized incident response and digital forensics capabilities designed for the most complex, high-severity cyber incidents. Recognized by international advisory and analyst agencies for its technical depth, Group-IB’s elite responders are trusted to handle intrusions involving advanced threat actors and sophisticated attack techniques. Supported by adversary-centric threat intelligence and continuous monitoring from CERT-GIB, the company delivers fast, precise, and intelligence-driven response operations that help organizations contain and recover from their most critical threats.

Group-IB customers can find out more about how Group-IB discovered two previously unknown zero-day vulnerabilities in widely used enterprise products: Cisco Unified Contact Center Express (UCCX) and IBM Sterling on its Threat Intelligence platform here.

About Group-IB

Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, citizens, and support law enforcement operations.

Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, Central Asia, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities.

Group-IB’s decentralized and autonomous operational structure helps it offer tailored, comprehensive support services with a high level of expertise. We map and mitigate adversaries’ tactics in each region, delivering customized cybersecurity solutions tailored to risk profiles and requirements of various industries, including retail, healthcare, gambling, financial services, manufacturing, crypto, and more.

The company’s global security leaders work in synergy with some of the industry’s most advanced technologies to offer detection and response capabilities that eliminate cyber disruptions agilely.

Group-IB’s Unified Risk Platform (URP) underpins its conviction to build a secure and trusted cyber environment by utilizing intelligence-driven technology and agile expertise that completely detects and defends against all nuances of digital crime. The platform proactively protects organizations’ critical infrastructure from sophisticated attacks while continuously analyzing potentially dangerous behavior all over their network.

The comprehensive suite includes the world’s most trusted Threat Intelligence, The most complete Fraud Protection, AI-powered Digital Risk Protection, Multi-layered protection with Managed Extended Detection and Response (XDR), All-infrastructure Business Email Protection, and External Attack Surface Management.

Furthermore, Group-IB’s full-cycle incident response and investigation capabilities have consistently elevated industry standards. This includes the 77,000+ hours of cybersecurity incident response completed by our sector-leading DFIR Laboratory, more than 1,400 successful investigations completed by the High-Tech Crime Investigations Department, and round-the-clock efforts of CERT-GIB.

Time and again, its solutions and services have been revered by leading advisory and analyst agencies such as Aite Novarica, Gartner®, Forrester, Frost & Sullivan, KuppingerCole Analysts AG, and more.

Being an active partner in global investigations, Group-IB collaborates with international law enforcement organizations such as INTERPOL, EUROPOL and AFRIPOL to create a safer cyberspace. Group-IB is also a member of the Europol European Cybercrime Centre’s (EC3) Advisory Group on Internet Security, which was created to foster closer cooperation between Europol and its leading non-law enforcement partners.