Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2330 articles · 161056 vulns · 36/41 feeds (7d)
← Back to list
8.6
CVE-2026-20230EXPLOITEDPATCHED
cis · unified communications

CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma

Description

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

Affected Products

VendorProductVersions
cisunified communicationsN/A, 14SU6, 15SU5, 14, 15

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisunified communications manager (cucm)cert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW

Related News (10 articles)

Tier E
Hacker News2d ago
Yet another Cisco SD-WAN 0-day under attack, and no patch in sight
→ No new info (linked only)
Tier B
BSI Advisories3d ago
[NEU] [hoch] Cisco Unified Communications Manager (CUCM): Schwachstelle ermöglicht Manipulation von Dateien
→ No new info (linked only)
Tier D
The Hacker News4d ago
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
→ No new info (linked only)
Tier D
The Hacker News4d ago
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
→ No new info (linked only)
Tier D
BleepingComputer4d ago
Cisco warns of critical Unified CM flaw with PoC exploit code
→ No new info (linked only)
Tier D
SecurityWeek4d ago
Cisco Warns of Available PoC for Critical Unified CM Vulnerability
→ No new info (linked only)
Tier D
Heise Security4d ago
Cisco stopft kritische Lücke in Unified CM und mehr
→ No new info (linked only)
Tier B
CERT-FR5d ago
Vulnérabilité dans les produits Cisco (04 juin 2026)
→ No new info (linked only)
Tier B
CCCS Canada5d ago
Cisco security advisory (AV26-547)
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-20230 | Cisco Unified Communications Manager WebDialer Service server-side request forgery (cisco-sa-cucm-ssrf-cXPnHcW)
→ No new info (linked only)
CVSS 3.18.6 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
null
CWECWE-918
PublishedJun 3, 2026
Last enriched4d agov6
Tags
cisco-sa-cucm-ssrf-cXPnHcW
Trending Score59
Source articles10
Independent9
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20182EXPKEV
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Trending: 111
HIGHCVE-2026-20245EXP
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
Trending: 91
HIGHCVE-2026-20233EXP
Cisco Webex Meetings Cross-Site Scripting Vulnerability
Trending: 36
HIGHCVE-2026-20175EXP
Cisco Finesse File Inclusion Vulnerability
Trending: 33
CRITICALCVE-2026-20223EXP
Cisco Secure Workload Unauthorized API Access Vulnerability
Trending: 8

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 3, 2026
Discovered by ZDM
Jun 3, 2026
Updated: affectedVersions, severity, exploitAvailable, activelyExploited
Jun 3, 2026
Updated: tags
Jun 3, 2026
Actively Exploited
Jun 4, 2026
Exploit Available
Jun 4, 2026
Patch Available
Jun 4, 2026
Updated: affectedVersions
Jun 4, 2026
Updated: patchAvailable, severity
Jun 4, 2026
Updated: affectedVersions, patchAvailable
Jun 4, 2026

Version History

v6
Last enriched 4d ago
v6Tier B4d ago

Updated affected versions to include versions 14 and 15 prior to 14SU6 and 15SU5, and noted that the patch will be available in September 2026.

affectedVersionspatchAvailable
via CERT-FR
v5Tier D4d ago

Updated severity to CRITICAL and added patch version 15SU5.

patchAvailableseverity
via Heise Security
v4Tier D4d ago

Updated severity to CRITICAL, added affected versions 14SU6 and 15SU5, and specified patch available in version 15SU5.

affectedVersions
via Heise Security
v3Tier C5d ago

Updated description with new details about the WebDialer Service and added a new tag.

tags
via VulDB
v2Tier B5d ago

Updated affected versions to include 14SU6 and 15SU5, changed severity to CRITICAL, and noted that exploit code is available.

affectedVersionsseverityexploitAvailableactivelyExploited
via CCCS Canada
v15d ago

Initial creation