Cisco
Cisco Unified Communications Manager: vulnerabilities and CVEs
Cisco Unified Communications Manager has 241 published vulnerabilities, 2 of them in the last 12 months. 5 are rated critical and 3 are listed by CISA as actively exploited.
CVEs241
Last 12 months2
Critical5
Actively exploited3
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20230 | High (8.6) | 88% | ⚠ Active exploitation | Jun 3, 2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct… |
| CVE-2026-20045 | Critical (9.8) | 4.5% | ⚠ Active exploitation | Jan 21, 2026 | — |
| CVE-2021-44228 | Critical (10) | 100% | ⚠ Active exploitation | Dec 10, 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20230 | High (8.6) | 88% | ⚠ Active exploitation | Jun 3, 2026 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct… |
| CVE-2026-20045 | Critical (9.8) | 4.5% | ⚠ Active exploitation | Jan 21, 2026 | — |
| CVE-2025-20361 | Medium (4.8) | 0.22% | — | Oct 1, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2025-20326 | High (8.8) | 0.18% | — | Sep 3, 2025 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote… |
| CVE-2025-20309 | Critical (10) | 1.2% | — | Jul 2, 2025 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an… |
| CVE-2025-20278 | Medium (6.7) | 0.18% | — | Jun 4, 2025 | A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the… |
| CVE-2020-3532 | Medium (6.1) | 0.50% | — | Nov 18, 2024 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM… |
| CVE-2020-3420 | Medium (5.4) | 0.42% | — | Nov 18, 2024 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2024-20511 | Medium (6.1) | 0.32% | — | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2024-20488 | Medium (6.1) | 0.37% | — | Aug 21, 2024 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2024-20375 | High (7.5) | 0.74% | — | Aug 21, 2024 | A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2024-20253 | Critical (10) | 2.4% | — | Jan 26, 2024 | A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due… |
| CVE-2023-20259 | High (7.5) | 0.61% | — | Oct 4, 2023 | A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management… |
| CVE-2023-20266 | High (7.2) | 0.49% | — | Aug 30, 2023 | A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow… |
| CVE-2023-20211 | High (8.8) | 0.79% | — | Aug 16, 2023 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2023-20242 | Medium (6.1) | 0.49% | — | Aug 16, 2023 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM &… |
| CVE-2023-20116 | Medium (5.7) | 0.60% | — | Jun 28, 2023 | A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2023-20010 | High (8.8) | 0.90% | — | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2022-20816 | High (8.1) | 1.2% | — | Aug 10, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2022-20862 | Medium (4.3) | 1.5% | — | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2022-20859 | High (8.8) | 1.3% | — | Jul 6, 2022 | A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection… |
| CVE-2022-20815 | Medium (6.1) | 0.76% | — | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM &… |
| CVE-2022-20800 | Medium (6.1) | 0.76% | — | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications… |
| CVE-2022-20791 | Medium (6.5) | 1.5% | — | Jul 6, 2022 | A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications… |
| CVE-2022-20752 | Medium (5.3) | 1.0% | — | Jul 6, 2022 | A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote… |
| CVE-2022-20804 | Medium (6.5) | 0.35% | — | Apr 21, 2022 | A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated,… |
| CVE-2022-20790 | Medium (6.5) | 1.9% | — | Apr 21, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an… |
| CVE-2022-20789 | Medium (6.5) | 1.4% | — | Apr 21, 2022 | A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated,… |
| CVE-2022-20788 | Medium (6.1) | 0.83% | — | Apr 21, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an… |
| CVE-2022-20787 | Medium (6.8) | 0.46% | — | Apr 21, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.