Cisco Product Security Update Advisory (CVE-2026-20230)

Cisco Product Security Update Advisory (CVE-2026-20230)

Overview

A security update has been released to address a vulnerability in Cisco products. The vulnerability is CVE-2026-20230, a server-side request forgery (SSRF) vulnerability discovered in Cisco Unified CM and Unified CM SME.

Affected Products

  • Cisco Unified CM version 14.
  • Cisco Unified CM version 15.
  • Unified CM SME version 14.
  • Unified CM SME version 15.

Resolution

A patch for CVE-2026-20230 is provided in the latest update. You must update to the latest version of the Vulnerability Patch following the instructions on the reference site.

Patch Versions

  • Cisco Unified CM 14SU6.
  • Cisco Unified CM 15SU5 or COP.
  • Unified CM SME 14SU6.
  • Unified CM SME 15SU5 or COP.

Reference

  • Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability.