CISCO has confirmed that a critical vulnerability, CVE-2026-20230, in its Unified Communications Manager and its session management edition has been exploited in the wild. The vulnerability, which has a CVSS score of 8.6, is due to improper validation of HTTP requests, enabling attackers to conduct Server Side Request Forgery (SSRF) attacks and potentially gain root access. Cisco initially released patches for the vulnerability in June, with another version expected in September. A proof-of-concept code for exploitation has been identified, prompting Cisco to urge customers to upgrade to the fixed software to mitigate risks.
Cisco Warns of Exploit in Manager SSRF Flaw CVE-2026-20230
CyberSIXT Evidence Panel
Article by CyberSIXT