HIGHVulnerability
Verified
Global

CISA KEV: Cisco Unified Communications Manager — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Analysis

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. Added to CISA Known Exploited Vulnerabilities catalog on 2026-06-25. Remediation due: 2026-06-28.

Indicators of Compromise (1)

CVE (1)
CVE-2026-20230
Source Attribution

Originally published by CISA KEV on Jun 25, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-103264 — Fleet versions before 4.87.0 contain an authentication bypass vulnerability in t...

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migr

CVE-2026-103264
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103255 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security

CVE-2026-103255
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103248 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.

CVE-2026-103248
NIST NVD