
CVE-2026-20230: Cisco Unified Communications Manager — Remote SSRF File Write (June 2026)
CVE-2026-20230 — Cisco Unified Communications Manager
CVE-2026-20230 is a critical server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager Server. It allows unauthenticated remote attackers to write arbitrary text files to affected systems using crafted HTTP requests. The flaw is actively exploited in the wild and has been added to CISA’s Known Exploited Vulnerabilities catalog. Severity is critical; immediate action is required.
Attack Vector
Attackers exploit this vulnerability by sending specially crafted HTTP requests to exposed Cisco Unified Communications Manager endpoints. No authentication is required. Successful exploitation enables remote file writes, which can be leveraged for further compromise, persistence, or lateral movement. There are no public IOCs, but traffic patterns involving unexpected HTTP POST or PUT requests to administrative endpoints should be scrutinized.
Who Is at Risk
All organizations running Cisco Unified Communications Manager Server are at risk, with US federal agencies specifically targeted per CISA. Any deployment exposing the management interface to untrusted networks is vulnerable. The risk is highest for unpatched systems accessible from the internet or internal threat actors.
Patch & Mitigate
- Patch: Apply Cisco’s official security update for Unified Communications Manager Server immediately. CISA has mandated a patch deadline for US federal agencies—refer to the CISA KEV catalog for the exact date.
- Workaround: No official workaround is available; patching is mandatory.
- Detect: Review web server and application logs for anomalous HTTP requests, especially unauthenticated attempts to write files or access sensitive endpoints. Monitor for new or unexpected files on the server.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers exploit the SSRF flaw to gain a foothold without credentials.
- TA0005 — Defense Evasion: Arbitrary file writes can be used to plant malicious scripts or alter configurations to evade detection.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

