LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20230: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 25, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities catalog on Jun 25, 2026, with a federal patch deadline of Jun 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that…

Cisco Unified Communications Manager contains a server-side request forgery vulnerability tracked as CVE-2026-20230. An unauthenticated remote attacker could exploit the flaw to write files on the underlying operating system, which could then be used to obtain root privileges.

The issue affects Cisco Unified Communications Manager and Unified Communications Manager Session Management Edition. Organizations that rely on these products for enterprise voice and video services should treat the vulnerability as a priority for inventory and remediation.

How it works

The weakness is classified under CWE-918, server-side request forgery. In this class of flaw an attacker supplies crafted input that causes the application to issue outbound requests to resources the attacker controls or to internal systems that would otherwise be unreachable.

Successful abuse can result in arbitrary file writes on the host operating system. Those files may later be leveraged to escalate privileges to root. The advisory does not document public exploit code or specific attack sequences; defenders should confirm exact mechanics against the vendor advisory.

Am I affected? How to find it in your systems

Cisco Unified Communications Manager typically runs on dedicated servers or virtual appliances that provide call control and session management. Begin by identifying all instances through configuration management databases, network discovery tools, or Cisco Smart Net Total Care reports.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. Confirm the exact patch or hotfix name and installation steps directly from Cisco documentation.

If you can't patch immediately

Until the update can be applied, reduce exposure through network segmentation that prevents unauthenticated external hosts from reaching Unified CM management interfaces.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches. Organizations can run a free exposure scan of their email domains to check for presence in known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Unified Communications Manager
WeaknessCWE-918
Added to CISA KEVJun 25, 2026
Federal patch deadlineJun 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities