CVE Tools

Unified Communications Manager

244 CVEs tracked. 3 of them are in CISA KEV.

This hub aggregates every CVE we track for Unified Communications Manager, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Unified Communications Manager CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Unified Communications Manager CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-061
2025-071
2025-080
2025-091
2025-100
2025-110
2025-120
2026-011
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 244 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical135%
  • High7631%
  • Medium15363%
  • Low10%

Latest CVEs

The 15 most recently published vulnerabilities affecting Unified Communications Manager.

  1. CVE-2026-20230Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability8.6
  2. CVE-2026-20045Cisco Unified Communications Products Remote Code Execution Vulnerability8.2
  3. CVE-2025-20326Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability4.3
  4. CVE-2025-20309Cisco Unified Communications Manager Static SSH Credentials Vulnerability10.0
  5. CVE-2025-20278Cisco Unified Communications Products Command Injection Vulnerability6.0
  6. CVE-2020-3420Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability5.4
  7. CVE-2024-20511Cisco Unified Communications Manager Cross-Site Scripting Vulnerability6.1
  8. CVE-2024-20488Cisco Unified Communications Manager Cross-Site Scripting Vulnerability6.1
  9. CVE-2024-20375A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could a...8.6
  10. CVE-2024-20253A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This ...9.9
  11. CVE-2023-20259A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the ...8.6
  12. CVE-2023-20266A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Co...6.5
  13. CVE-2023-20211A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could...8.1
  14. CVE-2023-20242A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communica...4.8
  15. CVE-2023-20116A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM ...6.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store