Server-Side Request Forgery Vulnerability in Cisco Unified Communications Products
CVE-2026-20230

8.6HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
3 June 2026

Badges

๐Ÿ“ˆ Trended๐Ÿ“ˆ Score: 2,510๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 20%๐Ÿ“ฐ News Worthy

What is CVE-2026-20230?

false

Affected Version(s)

Cisco Unified Communications Manager

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Cisco Unified CM CVE-2026-20230 is under active exploitation, allowing file writes on WebDialer-enabled systems.

2 hours ago

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks.

11 hours ago

Cisco Races to Patch Unified CM Flaw as Public Exploit Code Raises Stakes

Cisco patched CVE-2026-20230, a high-severity SSRF flaw in Unified Communications Manager that lets unauthenticated attackers write files and potentially gain root access when WebDialer is enabled. With public proof-of-concept code now available, organizations must act fast to update or disable the ...

3 weeks ago

References

EPSS Score

20% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ“ˆ

    Vulnerability started trending

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ“ฐ

    First article discovered by Securityweek

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.