Hackers have begun exploiting a critical security flaw in Cisco's Unified Communications platforms.
The vulnerability, indexed as CVE-2026-20230 , affects Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).
Cisco assigned the flaw a severity score of 8.6 out of 10 and released security updates earlier this month.
The company said the weakness stems from improper validation of certain HTTP requests, allowing an unauthenticated attacker to carry out server-side request forgery (SSRF) attacks against vulnerable devices.
Successful exploitation could enable attackers to write files to the underlying operating system, paving the way for privilege escalation and root-level access.
Cisco disclosed the vulnerability on 3rd June after it was reported by security researchers at SSD Secure , but at the time there was no evidence that it was being exploited.
That has now changed.
Threat intelligence company Defused Cyber said it detected active exploitation of the vulnerability over the weekend, describing attacks originating from a single internet address.
According to the researchers, the attackers are using specially crafted file:// requests to create files on vulnerable devices. The activity observed so far appears to be focused on identifying exposed systems rather than fully compromising them.
Researchers said the exploit attempts to create a text file named /tmp/cve-2026-20230-test.txt, suggesting the attackers are testing whether systems are vulnerable before launching more damaging attacks.
Security experts warned that the same flaw could be used to install web shells, execute malicious code and ultimately obtain full administrative control of affected servers.
Following reports of exploitation, SSD Secure released a technical analysis explaining the flaw.
The researchers said attackers could exploit the WebDialer component's handling of user-supplied URLs to write arbitrary files to the operating system using file:// URIs. By controlling both the destination path and the contents of those files, an attacker could achieve remote code execution and eventually gain root privileges.
The researchers noted that exploitation requires knowledge of the target device's hostname, but demonstrated that this information can be obtained from the system before launching the attack.
The vulnerability can only be exploited when the WebDialer service is enabled. Cisco said the service is disabled by default, limiting exposure for many deployments.
The company has patched the flaw in Unified CM 14SU6 and Unified CM SME 15SU5. Organisations unable to install the updates immediately are advised to disable the WebDialer service until patches can be applied.
Cisco has not yet updated its security advisory to indicate that the vulnerability is being actively exploited.
The incident continues a difficult year for the networking giant. Last week, Cisco disclosed that attackers were exploiting a separate vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2026-20262.
Earlier this year, the company addressed two critical zero-day vulnerabilities that were exploited before fixes became available.
One of them, CVE-2026-20045 , affected multiple Cisco collaboration products, including Unified Communications Manager, Unity Connection and Webex Calling Dedicated Instance, and was later added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue.
Another, CVE-2026-20127 , targeted Cisco Catalyst SD-WAN devices and was also exploited in attacks before patches were released.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
