CISCO Security Advisory

Published Date: July 1, 2026

CVE: CVE-2026-20230

Advisory Summary

🔐 ⚠️ Critical Server-Side Request Forgery Vulnerability in Cisco Unified Communications Manager ⚠️ 🔐

A critical security flaw (CVE-2026-20230) has been identified in Cisco Unified Communications Manager (Unified CM) and its Session Management Edition (SME). This vulnerability arises from improper input validation of specific HTTP requests, enabling unauthenticated remote attackers to perform server-side request forgery (SSRF) attacks.

This vulnerability poses a significant risk to communication infrastructure, potentially allowing attackers to gain full control over affected systems. Network security teams should treat this update with the highest priority to prevent possible breaches.

-20230

Reference: Vendor Advisory