Article

    Cyber News / Article / A Vulnerability in Cisco Products Could Allow for Server-Side Request Forgery

    A Vulnerability in Cisco Products Could Allow for Server-Side Request Forgery
    -2026-06-05

    A Vulnerability in Cisco Products Could Allow for Server-Side Request Forgery

    A vulnerability has been discovered in Cisco products that could allow for Server-Side Request Forgery. Cisco Unified Communications Manager (Unified CM) / Cisco Unified Communications Manager Session Management Edition (Unified CM SME) is Cisco’s central, software-based call control and session management platform for enterprise communication.

    Successful exploitation of this vulnerability could allow for Server-Side Request Forgery, where an attacker could write files to the underlying operating system that could be used later to elevate to root. Depending on the location the attacker is able to write files to, they may be able to execute commands or remotely access the affected device.

    There are currently no reports of these vulnerabilities being exploited in the wild. Proof of concept code appears to exist publicly.

    A vulnerability has been discovered in Cisco Products that could allow for Server-Side Request Forgery. Details of the vulnerability are as follows:

    Tactic: Initial Access(TA0001):

    Technique: Exploit Public-Facing Application(T1190):

    Successful exploitation of this vulnerability could allow for Server-Side Request Forgery, where an attacker could write files to the underlying operating system that could be used later to elevate to root. Depending on the location the attacker is able to write files to, they may be able to execute commands or remotely access the affected device.

    We recommend the following actions be taken:

    Copyright©2026 Center for Internet Security®

    Original source