Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2710 articles · 132320 vulns · 35/41 feeds (7d)
← Back to list
7.2
CVE-2026-20035PATCHED
Cisco · Cisco Unity Connection

Cisco Unity Connection Server-Side Request Forgery Vulnerability

Description

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.

Affected Products

VendorProductVersions
CiscoCisco Unity Connection12.5(1), 12.5(1)SU1, 12.5(1)SU2, 12.5(1)SU3, 12.5(1)SU4, 14, 12.5(1)SU5, 14SU1, 12.5(1)SU6, 14SU2, 12.5(1)SU7, 14SU3, 12.5(1)SU8, 14SU3a, 12.5(1)SU8a, 15, 15SU1, 14SU4, 12.5(1)SU9, 15SU2, 15SU3

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-20035 | Cisco Unity Connection up to 15SU3 HTTP server-side request forgery (cisco-sa-unity-rce-ssrf-hENhuASy)
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
15SU4
CWECWE-918
PublishedMay 6, 2026
Last enriched6h agov2
Trending Score27
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20188
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Connection Exhaustion Denial of Service Vulnerability
Trending: 47
HIGHCVE-2026-20034
Cisco Unity Connection Remote Code Execution Vulnerability
Trending: 31
HIGHCVE-2026-20167
Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability
Trending: 27
HIGHCVE-2026-20185
Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability
Trending: 27
MEDIUMCVE-2026-20168
Cisco IoT Field Network Director Path Traversal Vulnerability
Trending: 23

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 6, 2026
Discovered by ZDM
May 6, 2026
Updated: patchAvailable
May 6, 2026
Patch Available
May 6, 2026

Version History

v2
Last enriched 6h ago
v2Tier C6h ago

Updated severity to CRITICAL, noted that no exploit is available, and added patch available version 15SU4.

patchAvailable
via VulDB
v16h ago

Initial creation