Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-20230

Published 2026-06-03

Updated 2 months ago

Vendor/s

Cisco

Product/s

Unified Communications Manager

Version/s

14.0 > 14su6

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

8.6

/ 10

High

Severity Details

Base score

8.6 High

Attack vector

Network

Attack complexity

Low

Privileges required

None

User interaction

None

Scope

Changed

Confidentiality

None

Integrity

High

Availability

None

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2026-20230 is a critical SSRF vulnerability in Cisco Unified CM and SME that allows remote attackers to escalate to root privileges. Patches available.

## Why this matters

CVE-2026-20230 is a critical SSRF vulnerability in Cisco Unified Communications Manager. While its CVSS score is 8.6, Cisco classifies it as 'Critical' because successful exploitation allows unauthenticated remote attackers to write files to the underlying operating system and escalate to root privileges. Its inclusion on the CISA Known Exploited Vulnerabilities (KEV) list indicates active exploitation, significantly increasing the risk for organizations. Security teams must prioritize this because it bypasses authentication and can lead to full system compromise. Organizations with the WebDialer service enabled—the primary attack vector—are at immediate risk and require urgent remediation.

## CPE

Cisco

| Product                          | Version Start | Version End (excl.) | Status     |
| -------------------------------- | ------------- | ------------------- | ---------- |
| unified\_communications\_manager | 14.0          | 14su6               | vulnerable |
| unified\_communications\_manager | 14.0          | 14su6               | vulnerable |
| unified\_communications\_manager | 15.0          | 15su4a              | vulnerable |
| unified\_communications\_manager | 15.0          | 15su4a              | vulnerable |

## Related weakness (CWE)

CWE-918

## Remediation plan

1

### Apply official patches

Cisco has released software updates to address this SSRF vulnerability. Administrators should consult the Cisco Security Advisory (cisco-sa-cucm-ssrf-cXPnHcW) to identify and apply the appropriate fixed release for their specific deployment.

2

### Update affected systems

Upgrade Cisco Unified CM and SME instances to version 14su6 or later. For version 15.0 deployments, ensure you migrate to a release beyond 15su4a or apply the specific hotfixes recommended by Cisco to close the vulnerability.

3

### Restrict access

If immediate patching is not possible, disable the WebDialer service, which is a prerequisite for exploitation. Additionally, implement network access control lists (ACLs) to restrict access to the Unified CM management interface to trusted, authorized internal networks only.

4

### Monitor for exploitation

Audit system logs for unusual HTTP requests targeting the WebDialer service, specifically those containing suspicious URLs or file paths. Monitor the underlying operating system for unauthorized file creation or unexpected attempts to gain root-level access.

## Detection Guidance

Detection should focus on monitoring HTTP traffic to the WebDialer service for malformed requests or SSRF patterns. Security teams should use EDR tools to monitor for unexpected processes running with root privileges and audit system integrity for unauthorized file writes. Network-level signatures should flag outbound requests originating from the Unified CM that target internal infrastructure or sensitive metadata services, which may indicate an active SSRF exploit attempt.

## References

[https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW Vendor Advisory ](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW)[https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/ Exploit Third Party Advisory ](https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-20230 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
