Vulnerabilities
Cisco Unified CM CVE-2026-20230: A Public PoC for an Unauthenticated SSRF That Climbs to Root
Cisco patched CVE-2026-20230, an unauthenticated server-side request forgery flaw in Unified Communications Manager that lets a network attacker write files and escalate to root. Public proof-of-concept code is already out; Cisco's PSIRT reports no in-the-wild exploitation yet.