Cisco has confirmed that the CVE-2026-20230 vulnerability in its Unified Communications Manager (Unified CM) is currently being exploited. This vulnerability, which received a CVSS score of 8.6, allows for server-side request forgery (SSRF) attacks, enabling attackers to potentially gain root access to the system.
The issue is specific to systems where the WebDialer service is enabled. Fortunately, this feature is disabled by default, limiting the initial attack surface.
Patches addressing this vulnerability were originally released in early June 2023 for Unified CM version 14SU6, with plans to include them in the upcoming 15SU5 release expected in September. Despite these updates, attackers have already started exploiting the flaw.
Exploitation details surfaced around late June, noting that attackers are constructing payloads using file:// schemes to manipulate target devices. This comes after proof-of-concept exploit codes became publicly available, raising concerns about the vulnerability's active exploitation.
Cisco strongly recommends that users update their systems to the patched versions without delay to prevent potential security breaches. The company's advisories stress the urgency given the active exploitation occurring in the wild.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Cisco acknowledged that attackers are exploiting a vulnerability (CVE-2026-20230) in its Unified Communications Manager software, which could allow remote, unauthorized access. Customers are urged to update their systems immediately to prevent attacks, following reports of active exploitation after a previously issued patch.
Cisco has confirmed that a critical vulnerability (CVE-2026-20230) in its Unified CM is being actively exploited, allowing attackers to potentially gain root access. The vulnerability affects only appliances with the WebDialer service enabled, which is off by default, prompting Cisco to recommend immediate upgrades to patched software.