CISCO Security Advisory

Published Date: Not specified

CVE: CVE-2026-20314

Advisory Summary

🗓️ Published Date: 19 Aug 2026

📌 TITLE: Cisco Contact Center SSRF—Authenticated Remote Risk in Packaged CCE / Unified CCE

⚠️ ALARM: Server-Side Request Forgery (SSRF) via crafted HTTP
Cisco reports a vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) that could let an authenticated, remote attacker trigger SSRF. The attacker can coerce the affected server into making arbitrary outbound network requests, effectively using the contact center platform as a “proxy” for internal or external targeting.

🔐 ACTIONABLE: What market professionals should do now
1. Identify affected deployments of Packaged CCE / Unified CCE and inventory current versions.
2. Prioritize patching per Cisco guidance (plan change windows—contact center platforms often require coordinated service cutovers).
3. Harden network egress from the contact center servers (restrict outbound destinations wherever possible).
4. Review authentication exposure: ensure admin and application endpoints are protected (MFA, strong credential policies, least-privilege, and tighter access lists).
5. Monitor for SSRF indicators: unusual outbound requests from the contact center app layer, new destinations, or denied internal traffic patterns.

-2026-20314

Reference: Vendor Advisory