CVE-2026-20230 – Red Cisco Unified Communications Manager

CVSS 8.6 IMPORTANT

“Public exploit code turns this voice-platform bug into a fast-moving risk.”

Cisco patched CVE-2026-20230 in Cisco Unified Communications Manager. The issue is a server-side request forgery vulnerability that can allow an unauthenticated attacker to write files to the underlying operating system. The CVSS score is 8.6, which is High severity.

Public proof-of-concept code is available.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-918
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.