Vulnerabilities & Exploits · Web App Attack

Cisco Broadens Patch Scope Across Voice, Switches, IoT

Cisco’s latest advisory widens the blast radius beyond a single product line. The new issues turn Unity Connection into a root-level execution and SSRF pivot point, and they let malformed SNMP traffic reboot SG350 and SG350X switches, so the real risk is management-plane compromise and service disruption, not just another high-severity bug.

Cisco says CVE-2026-20034 and CVE-2026-20035 affect Unity Connection and can let remote authenticated attackers execute code as root or send requests from the device. CVE-2026-20185 affects SG350 and SG350X switches across SNMP 1, 2c, and 3, and Cisco also added a separate DoS flaw in IoT Field Network Director, broadening the patch set across voice, switching, and IoT management.

For operators, the key point is that these are different failure modes across different management planes. One set turns a communications platform into an internal request source and code-execution target, the other can drop network connectivity by forcing a switch reload.

3 sources · May 7

CVE-2026-20034

NVD KEV

CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote…

CVE-2026-20035

NVD KEV

CVSS 7.2 HIGH: a vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to…

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-05-06

Every edition of this story: Cisco Broadens Patch Scope Across Voice, Switches, IoT

More from today