CVE-2026-20035Disclosure(cisco / unity_connection)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco unity_connection systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unity_connection

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
unity_connection

9 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 105-0605-0705-08
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure2
2026-05-071
Disclosure1
2026-05-081
Patch1
Full discourse4 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Two high severity #vulnerabilities in #Cisco Unity Connection. While #CVE-2026-20034 CVSS: 8.8 could lead to arbitrary code execution #RCE, #CVE-2026-20035 CVSS: 7.2 allows a remote attacker to conduct Server-Side Request Forgery #SSRF attacks. #Patch #Patch #Patch

    Post summary

    The post alerts to two high‑severity Cisco Unity Connection CVEs—#2026‑20034 (RCE, CVSS 8.8) and #2026‑20035 (SSRF, CVSS 7.2)—and notes that patches are available, with no evidence of active exploitation or PoC.

    00020334
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-20034 CVE-2026-20035 Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy

    Post summary

    The post announces two new Cisco Unity Connection vulnerabilities, CVE-2026-20034 and CVE-2026-20035, that allow remote code execution and SSRF, providing a link to Cisco’s official advisory.

    00010351
    6.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20035 A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. … https://www.cve.org/CVERecord?id=CVE-2026-20035

    Post summary

    The text announces a newly identified vulnerability (CVE-2026‑20035) in Cisco Unity Connection Web Inbox that allows unauthenticated remote attackers to perform SSRF attacks via the web UI.

    00000114
    57.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-20035 A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to co… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-20035 #Cisco #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-20035, highlighting a high‑severity flaw in Cisco Unity Connection Web Inbox's web UI that permits unauthenticated remote exploitation, with a CVSS score of 7.2, but provides no PoC, exploit code, or patch details.

    0000045
    482 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appciscounity_connection---
Appciscounity_connection14.0--
Appciscounity_connection14su1--
Appciscounity_connection14su2--
Appciscounity_connection14su3--
Appciscounity_connection14su4--
Appciscounity_connection15.0--
Appciscounity_connection15su1--
Appciscounity_connection15su2--
Appciscounity_connection15su3--

Explore more