Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server

Public Sector Action
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited SSRF flaw. The vulnerability was added to CISA's KEV catalog under BOD 26-04, making remediation urgent for covered agencies. Cisco had already labeled the bug critical and warned it could be exploited remotely without authentication.

Related Happenings

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

Progress ShareFile Storage Zone Controller access disruption

Service Disruption
H score53 First: 10.07.2026 19:30 Last: 10.07.2026 19:30 Sources 1

About this happening: ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...

Latest development: 14.07.2026 19:08

Progress confirmed a high-severity zero-day path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller and released versions 5.12.5 and 6.0.2 to patch the flaw. Progress said the update follows the emergency shutdown of affected controllers and that it has no indication of unauthorized access to any ShareFile customer account or data.

Cisco Unified CM SSRF root-privilege flaw (CVE-2026-20230)

Vulnerability
H score49 First: 04.06.2026 14:09 Last: 04.06.2026 14:09 Sources 1

How related: Last weekend, threat detection startup Defused observed the vulnerability being exploited in attacks to write arbitrary text files to affected endpoints.

About this happening: CVE-2026-20230 exposes Cisco Unified CM systems with WebDialer enabled to remote SSRF abuse that can lead to root-level compromise. The flaw can be triggered w...

Latest development: 26.06.2026 22:43

Cisco released a patch for CVE-2026-20230 in Cisco Unified Communications Manager Server and warned that the critical server-side request forgery flaw could be exploited remotely and without authentication via specially crafted HTTP requests.

Cisco Unified Communications Manager security update for CVE-2026-20230

Security Patch Release
H score56 First: 04.06.2026 14:09 Last: 04.06.2026 14:09 Sources 1

About this happening: Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...

Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)

Vulnerability
H score60 First: 14.05.2026 23:09 Last: 14.05.2026 23:09 Sources 1

About this happening: CVE-2026-20182 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, creating a path to administr...

Latest development: 14.05.2026 23:25

Cisco released a patch for CVE-2026-20182, giving organizations using Cisco Catalyst SD-WAN Controllers a way to block the authentication bypass before UAT-8616 can continue using it for administrative access, SSH key insertion, NETCONF changes, and root escalation.

Timeline

  1. 26.06.2026 22:43 1 articles · 19d ago

    Cisco releases patch for CVE-2026-20230 in Unified Communications Manager Server

    Mitigation Patch Update

    Cisco released a patch for CVE-2026-20230 in Cisco Unified Communications Manager Server on June 3 after marking the server-side request forgery flaw critical, warning that specially crafted HTTP requests could exploit it remotely without authentication.

    Show sources
  2. 26.06.2026 22:43 2 articles · 19d ago

    CISA adds CVE-2026-20230 to KEV and orders federal agencies to patch by June 28

    Legal Policy Action Update

    CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch Cisco Unified Communications Manager Server by Sunday, June 28 under BOD 26-04 after the flaw was identified as actively exploited and used to write arbitrary text files to affected endpoints.

    Show sources