LIVE · cybersecurity feed
Live wire
cve recordhighexploited in the wild

CVE-2026-20230

Cisco · Unified Communications Manager · Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Published · Added to CISA KEV
CVSS8.6
Severityhigh
WeaknessCWE-918
ExploitedYes, in CISA KEV
Ransomware useUnknown
Federal fix dueJun 28, 2026

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Crit

Required action (CISA)

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-20230

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-20230.