VORANT. Threat Intelligence Sign in Get the full feed

Cisco Unified Communications Manager has a server-side request forgery vulnerability…

high vulnerability telecommunications

Cisco Unified Communications Manager has a server-side request forgery vulnerability (CVE-2026-20230) affecting versions 14 and 15.

The French CERT (ANSSI) has disclosed a server-side request forgery (SSRF) vulnerability affecting multiple versions of Cisco Unified Communications Manager and Unified Communications Manager Session Management Edition. The vulnerability impacts version 14 releases prior to 14SU6 and version 15 releases prior to 15SU5 or COP1 for both product lines.

SSRF vulnerabilities allow attackers to abuse the trust relationship between a vulnerable server and other systems, potentially enabling unauthorized access to internal resources, data exfiltration, or reconnaissance of internal network architecture. The vulnerability is tracked as CVE-2026-20230.

Cisco has published a security advisory with remediation guidance. Organizations should consult the vendor bulletin and apply patches according to their deployment schedule. Version 15SU5 is expected to be available in September 2026.

Mentioned in this report

Vulnerabilities CVE-2026-20230KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0689

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free