CVE-2026-20034
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote…
Vulnerabilities & Exploits · Web App Attack
Cisco’s latest advisory widens the blast radius beyond a single product line. The new issues turn Unity Connection into a root-level execution and SSRF pivot point, and they let malformed SNMP traffic reboot SG350 and SG350X switches, so the real risk is management-plane compromise and service disruption, not just another high-severity bug.
Cisco says CVE-2026-20034 and CVE-2026-20035 affect Unity Connection and can let remote authenticated attackers execute code as root or send requests from the device. CVE-2026-20185 affects SG350 and SG350X switches across SNMP 1, 2c, and 3, and Cisco also added a separate DoS flaw in IoT Field Network Director, broadening the patch set across voice, switching, and IoT management.
For operators, the key point is that these are different failure modes across different management planes. One set turns a communications platform into an internal request source and code-execution target, the other can drop network connectivity by forcing a switch reload.
3 sources · May 7
CVSS 8.8 HIGH: a vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote…
CVSS 7.2 HIGH: a vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to…
SecurityWeek
Cisco Patches High-Severity Vulnerabilities in Enterprise Products
Successful exploitation of the flaws could lead to code execution, server-side request forgery attacks, and denial-of-service conditions.
originalCisco PSIRT
Cisco Security Advisory: Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
originalCisco PSIRT
Cisco Security Advisory: Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code on or conduct server-side request forgery (SSRF) attacks through an affected device.
originalPart of the PlainSec briefing for 2026-05-06
Every edition of this story: Cisco Broadens Patch Scope Across Voice, Switches, IoT