Cisco Product Security Update Advisory (CVE-2026-20230)
Overview
A security update has been released to address a vulnerability in Cisco products. The vulnerability is CVE-2026-20230, a server-side request forgery (SSRF) vulnerability discovered in Cisco Unified CM and Unified CM SME.
Affected Products
- Cisco Unified CM version 14.
- Cisco Unified CM version 15.
- Unified CM SME version 14.
- Unified CM SME version 15.
Resolution
A patch for CVE-2026-20230 is provided in the latest update. You must update to the latest version of the Vulnerability Patch following the instructions on the reference site.
Patch Versions
- Cisco Unified CM 14SU6.
- Cisco Unified CM 15SU5 or COP.
- Unified CM SME 14SU6.
- Unified CM SME 15SU5 or COP.
Reference
- Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability.