Skip to main content
Change Risk Intel

CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

CVSS
9.8 (Critical)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — CUCM is a Tier-1 telephony platform; patch within the next scheduled voice maintenance window (typically weekly) and monitor for outbound HTTP from the CUCM host.
Affected products
Cisco Unified Communications Manager

Why this one matters to a CAB

Cisco Unified Communications Manager is the enterprise telephony core. A server-side request forgery that lets an unauthenticated attacker write files to the underlying OS, escalating to root, is the worst class of CVE for a Tier-1 real-time voice platform — because CUCM outages are noticed by everyone with a phone in five minutes flat.

Defender’s angle

  • Voice change discipline: CUCM patch windows are traditionally weekly (usually Sunday 02:00 local). Do not skip a week to wait for a bundle; this CVE justifies a dedicated window.
  • HTTP egress from the CUCM tier: baseline outbound HTTP from every CUCM node. The exploit needs an outbound leg to be useful. A CUCM cluster that never talks to the internet has already neutralized most of the attacker payload.
  • CTL rotation: after patching, rotate the CTL and ITL files in the CUCM cluster. Root on the underlying OS is game-over for the certificate trust store.

What to bring to CAB

A voice-team-owned change record. Include a phone-team on-call handoff for the 30 minutes surrounding the patch, and a communication to the desk-phone user base that call quality may briefly degrade.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.