Cisco Unified Communications Manager Vulnerability CVE-2026-20230 Allows Remote Exploitation
Apply the Cisco Unified Communications Manager patch for CVE-2026-20230 immediately to close the remote exploitation vector.
Apply the Cisco Unified Communications Manager patch for CVE-2026-20230 immediately.
Summary
Security researchers have uncovered a critical flaw in Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME), catalogued as CVE‑2026‑20230. The vulnerability, with a CVSS score of 8.6, stems from improper input validation for specific HTTP requests, allowing unauthenticated remote attackers to exploit the system. The flaw could lead to remote code execution or privilege escalation, compromising the integrity of Cisco's unified communications infrastructure.
Cisco has released a patch to address the issue, and the flaw is actively being exploited in the wild. The advisory urges administrators to apply the patch immediately to mitigate the high‑severity risk. Failure to patch could expose corporate networks to remote exploitation.
Key changes
- CVE-2026-20230 in Cisco Unified Communications Manager and Unified CM SME
- CVSS 8.6, improper input validation for specific HTTP requests
- Allows unauthenticated remote attacker to exploit the system
- Could lead to remote code execution or privilege escalation
- Cisco has released a patch to address the issue
- Flaw is actively being exploited in the wild