CVE-2026-20230
Coverage of CVE-2026-20230 in the Nexus archive.
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Threat actors are exploiting a critical security flaw in Cisco Unified Communications Manager and Unified CM SME, tracked as CVE-2026-20230, which allows unauthenticated remote attackers to exploit improper HTTP request input validation. The vulnerability has a CVSS score of 8.6 and enables a path to root file-write capabilities.
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
A high-severity SSRF vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager Server is currently being exploited in attacks. The flaw allows attackers to manipulate the system through server-side request forgery.
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a server-side request forgery vulnerability (CVE-2026-20230) in Unified Communications Manager, allowing unauthenticated attackers to write files and escalate to root. Proof-of-concept exploit code is now public, though Cisco's PSIRT reports no observed attacks yet.