Skip to content

CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks

Cybersecuritynews Guru Baran June 26, 2026

CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to apply patches immediately amid active exploitation in the wild. The flaw, tracked as CVE-2026-20230, enables unauthenticated remote attackers to perform server-side request forgery (SSRF) attacks […]