Cisco has officially confirmed active exploitation of CVE-2026-20230, a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM). The flaw, patched in early June 2026, allows unauthenticated remote attackers to send crafted HTTP requests using file:// payloads to write files on targeted devices. Threat intelligence firm Defused first reported active exploitation on June 22, followed by a technical write-up with a proof-of-concept from SSD Secure. Cisco now urges customers to upgrade to Unified CM versions 14SU6 or 15SU5, and advises disabling the vulnerable WebDialer service as a temporary mitigation. Shadowserver is tracking over 200 exposed Unified CM instances online, primarily in Asia and North America.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
124 Impressions