All CVEs
Vulnerability intelligence

CVE-2026-20230

CWE-918

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.

CVSS Score
8.6
High
EPSS — Exploit Probability
42%
Riskier than 99% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-25
Remediation
Patch available
Federal deadline 2026-06-28
NVD entry Vendor patch PoC / advisory CISA KEV

16 articles across 8 outlets · first covered Jun 4, 2026 · latest Jul 2, 2026

Tracked incidents

Coverage timeline