$ intel.mask2.ca

ADVISORY · 2026-06-11 · SRC MS-ISAC · HIGH
2026-06-11 high REL 7/10

Cisco Unified Communications Manager SSRF Vulnerability Enables File Write and Root Escalation

post-secondaryhealthcaregovernmentfinanceenergy

A server-side request forgery vulnerability in Cisco Unified Communications Manager and Unified CM Session Management Edition could allow attackers to write files to the underlying operating system. Successful exploitation may lead to privilege escalation to root, command execution, or remote device access depending on file write location.

Why it matters in Western Canada: Many Western Canadian post-secondary institutions, healthcare organizations, and enterprise sectors deploy Cisco Unified Communications for campus and corporate telephony and collaboration. Exploitation could compromise voice systems and enable lateral movement within critical infrastructure.


Summary generated from the original advisory. Read the full source: ms-isac

Source
https://www.cisecurity.org/advisory/a-vulnerability-in-cisco-products-could-allow-for-server-side-request-forgery_2026-053
CVEs
None listed
Tags
cisco, ssrf, unified-cm, privilege-escalation, voip
Provenance
mask2-ti-pipeline (AI-assisted, human-reviewable)