Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-20230

Published 2026-06-03
Updated 2 months ago
Vendor/s
Cisco
Product/s
Unified Communications Manager
Version/s
14.0 > 14su6
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
8.6
/ 10
High
Severity Details
Base score
8.6 High
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None

Description

CVE-2026-20230 is a critical SSRF vulnerability in Cisco Unified CM and SME that allows remote attackers to escalate to root privileges. Patches available.

CPE

Cisco logo
Cisco
Product Version Start Version End (excl.) Status
unified_communications_manager 14.0 14su6 vulnerable
unified_communications_manager 14.0 14su6 vulnerable
unified_communications_manager 15.0 15su4a vulnerable
unified_communications_manager 15.0 15su4a vulnerable

Related weakness (CWE)

CWE-918

Remediation plan

1

Apply official patches

Cisco has released software updates to address this SSRF vulnerability. Administrators should consult the Cisco Security Advisory (cisco-sa-cucm-ssrf-cXPnHcW) to identify and apply the appropriate fixed release for their specific deployment.

2

Update affected systems

Upgrade Cisco Unified CM and SME instances to version 14su6 or later. For version 15.0 deployments, ensure you migrate to a release beyond 15su4a or apply the specific hotfixes recommended by Cisco to close the vulnerability.

3

Restrict access

If immediate patching is not possible, disable the WebDialer service, which is a prerequisite for exploitation. Additionally, implement network access control lists (ACLs) to restrict access to the Unified CM management interface to trusted, authorized internal networks only.

4

Monitor for exploitation

Audit system logs for unusual HTTP requests targeting the WebDialer service, specifically those containing suspicious URLs or file paths. Monitor the underlying operating system for unauthorized file creation or unexpected attempts to gain root-level access.

Detection Guidance

Detection should focus on monitoring HTTP traffic to the WebDialer service for malformed requests or SSRF patterns. Security teams should use EDR tools to monitor for unexpected processes running with root privileges and audit system integrity for unauthorized file writes. Network-level signatures should flag outbound requests originating from the Unified CM that target internal infrastructure or sensitive metadata services, which may indicate an active SSRF exploit attempt.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management