Dossier
PSIRT
Coverage of PSIRT in the Nexus archive.
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a server-side request forgery vulnerability (CVE-2026-20230) in Unified Communications Manager, allowing unauthenticated attackers to write files and escalate to root. Proof-of-concept exploit code is now public, though Cisco's PSIRT reports no observed attacks yet.