Security
Loading…

CVE-2026-20230

UNKNOWNKnown Exploited
Description

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Timeline
Published:June 25th, 2026 12:00 AM
Last modified:June 25th, 2026 12:00 AM
Added to KEV:June 25th, 2026
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Cisco

Products

Unified Communications Manager
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute