🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Cisco Unified Communications Manager SSRF Arbitrary File Write (CVE-2026-20230) | MSSP Advisory
Critical🔴 KEV ALERTConfirmed
DateJune 25, 2026
CVECVE-2026-20230
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-20230 to the Known Exploited Vulnerabilities catalog, confirming active exploitation of a server-side request forgery flaw in Cisco Unified Communications Manager. An unauthenticated remote attacker can write arbitrary files to the underlying OS and use those files as a stepping stone to root access. The patch deadline is June 28, 2026, but exploitation is already underway and waiting until that date is not a viable posture.
⚠️Why It Matters for MSSPs
Cisco Unified CM is common in mid-market and enterprise client environments that MSSPs manage, meaning your clients are likely running this right now and you carry the advisory obligation to tell them before they find out another way. Your own internal communications infrastructure may also run Unified CM or Unified CM SME, which means an attacker could use this flaw to gain root on a system inside your management environment and pivot toward your RMM or PSA from there.
✅Recommended Action
In the next 24 hours, pull your asset inventory and your client asset inventories and identify every instance of Cisco Unified CM and Unified CM SME that is internet-exposed or reachable from an internet-facing segment. Apply Cisco's vendor patches immediately on any identified instance and send a direct client notification today, not at end of week, so your clients have the information they need to make patching decisions on systems you do not directly manage.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.