← Intelligence Center

Cisco Unified Communications Manager Vulnerability Could Allow for Server-Side Request Forgery (CVE-2026-20230)

PublishedJun 5, 2026
Updated
VendorCisco
SeverityMedium
Known ExploitedNo
Advisory IDINTEL-000010
CVEs
CVE-2026-20230
Products
  • Cisco Unified Communications Manager and Session Management Edition 14 prior to 14SU
  • Cisco Unified Communications Manager and Session Management Edition 15 prior to 15SU5 (Sep 2026) or COP

Executive Summary

MS-ISAC Advisory 2026-053 (issued 6/5/2026): a vulnerability in Cisco Unified Communications Manager and Session Management Edition is remotely exploitable without authentication and could allow for Server-Side Request Forgery, allowing an attacker to write arbitrary files to the system, including auto-executed locations, and potentially run remote commands or access the device remotely. Exploitation requires the WebDialer service to be enabled (disabled by default). There are currently no reports of exploitation in the wild, but public proof-of-concept code appears to exist.

Municipal Impact

MS-ISAC rates the risk as Medium for large, medium, and small government entities. Municipalities using Unified CM in internet-facing or poorly segmented environments are at heightened risk.

SMB Impact

MS-ISAC rates the risk as Medium for large, medium, and small business entities; not applicable to home users.

Recommended Actions

  1. Apply appropriate updates provided by Cisco to vulnerable systems immediately after appropriate testing.
  2. Ensure Unified CM is not deployed in internet-facing or poorly segmented environments.
  3. Follow CIS Safeguards for vulnerability management, automated vulnerability scanning, and remediation.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter