CVE-2026-20230: Cisco Unified Communications Manager
EPSS88.2%No. 498 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV100
Same product2
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | Unified Communications Manager |
| Name | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability |
| Added to KEV | 2026-06-25 |
| US federal due date | 2026-06-28 |
| Ransomware use | Unknown |
| CWE | CWE-918 |
CISA description
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-20045 | Cisco Unified Communications Manager | 2026-01-21 | 4.5% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco Unified Communications Manager vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-25.