Cisco issues security updates to address a critical vulnerability in Unified Communications Manager (Unified CM), identified as CVE-2026-20230. The flaw can be exploited remotely and does not require authentication. Reported attack paths involve server-side request forgery (SSRF), where an attacker can induce the server to make unauthorized requests and write files to the system. From there, the attacker can escalate privileges to obtain root access. Multiple outlets report that proof-of-concept (PoC) exploit code is already available publicly, which can lower the effort needed to test or attempt exploitation. Cisco’s PSIRT indicates it has not observed the vulnerability being used in attacks at the time of reporting. The updates are aimed at preventing exploitation described in the PoC and mitigating the risk of file writing and subsequent privilege escalation. Organizations running affected Unified CM deployments are advised to apply Cisco’s released patches and follow vendor guidance to reduce exposure.