Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N C N H N 8.6 .8321 99.7 YES
AFFECTED
Product Versions Fixed
Cisco Unified Communications Manager 14 – —
TIMELINE
Oct 8 Reserved by cisco
Jun 25 Added to CISA KEV, remediation due 2026-06-28
Jun 25 Published (CNA: cisco)
Jun 29 DUE DATE PASSED — CVE-2026-20230 (Cisco Unified Communications Manager). CISA remediation deadline was June 28, 2026; still in catalog.
Jul 22 ENRICHED — CVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD.
Jul 22 EXPLOIT PUBLISHED — CVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added.
Description
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
Lifecycle
Complete event history — 6 events, chronological
| Date | Event | Detail |
| October 8, 2025 | Reserved | Reserved by cisco |
| June 25, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-06-28 |
| June 25, 2026 | Published | Published (CNA: cisco) |
| June 29, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-20230 (Cisco Unified Communications Manager). CISA remediation deadline was June 28, 2026; still in catalog. |
| July 22, 2026 | ENRICHED | ENRICHED — CVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD. |
| July 22, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco Unified Communications Manager | — | 14 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-20230 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.