Exploited Vulnerabilities Daily
🌐 English

Home › Cisco

CVE-2026-20230: Cisco Unified Communications Manager

EPSS88.2%No. 498 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV100
Same product2
FieldValue
VendorCisco
ProductUnified Communications Manager
NameCisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Added to KEV2026-06-25
US federal due date2026-06-28
Ransomware useUnknown
CWECWE-918

CISA description

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-20045Cisco Unified Communications Manager2026-01-214.5%Unknown

NVD — CVE-2026-20230

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Cisco Unified Communications Manager vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-25.