High Known exploited (KEV) CVE-2026-20230

SSRF in Cisco Unified Communications Manager (CVE-2026-20230) — unauthenticated file writes that can lead to root

Cisco Unified Communications Manager Added to KEV Jun 25, 2026 Federal remediation due 2026-06-28

Cisco Unified Communications Manager (Unified CM / SME), the call-control heart of enterprise IP telephony, contains a server-side request forgery (SSRF) flaw. A remote, unauthenticated attacker can write files to the underlying OS, usable later to escalate to root. CISA added it to KEV on June 25, 2026, with remediation due three days later, on June 28.

Key facts

  • CVE IDCVE-2026-20230
  • CVSS base score8.6 HIGH
  • Affected (vendor / product)Cisco Unified Communications Manager
  • CWECWE-918
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-06-28 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • SSRF (CWE-918) in Cisco Unified CM / SME — the server is made to issue internal requests on the attacker's behalf
  • A remote, unauthenticated attacker can write files to the underlying OS, usable later to escalate to root
  • NVD assessment: CVSS 8.6 (HIGH)
  • Added to KEV June 25, 2026 (confirmed exploitation); remediation due June 28 — a 3-day deadline (BOD 26-04)
  • Call-control platforms are hard to take down, sit deep in networks, and run long — prime ground for persistent footholds

SSRF (server-side request forgery) means tricking a server into sending requests on the attacker's behalf. A server enjoys far greater privilege and reach toward internal networks and its own services than any outsider; SSRF abuses that trust to arrive at internals that should be out of reach.

Here, an unauthenticated remote attacker can get as far as writing files onto the underlying OS — a stepping stone to seizing root (the highest privilege on Linux-based systems). "No authentication required" combined with "a path to total system control" is what drives the severity.

The target matters, too. Unified CM is the IP-era telephone exchange — it concentrates an enterprise's calls, conferencing, and contact flow. Because taking it down stops business communication, patching tends to be deferred; it sits deep in the network, runs for years, and is thinly monitored.

Those are ideal conditions for an attacker building a persistent foothold, and they match the recent pattern of attacks against communications infrastructure.

The KEV listing means exploitation has been confirmed in the wild, and the 3-day deadline marks top-priority handling under BOD 26-04. Applying Cisco's fixed release per its advisory is the baseline — and this is also the moment to check how far the calling platform is reachable from outside, and to look for signs of compromise such as unexpected files or accounts.

Why it matters

Compromise of the calling platform leads directly to eavesdropping, communication outages, and a deep-network foothold. Beyond patching, organizations running Unified CM should confront the structural issue — infrastructure that is "too critical to restart" gets patched last — by securing maintenance windows and restricting reachability. A concrete case study in the targeting of communications infrastructure.

FAQ

What kind of attack is SSRF?
Making the server issue internal requests on the attacker's behalf. It abuses the server's privileged reach into internal networks to touch things outsiders cannot. Here it can be used to write files onto the OS.
Does it hand over root directly?
The record describes a two-step path: files written now can later be used to escalate to root. Not a direct hit, but opening a road from unauthenticated remote access to top privilege is serious in itself.
What should I do?
Apply the fixed release per Cisco's security advisory. CISA requires BOD 26-04-based prioritization. Also review the platform's external reachability and check for suspicious files or accounts.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Cisco#Unified Communications Manager#SSRF#CWE-918#KEV#IP telephony
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.