Oodaloop Cisco Confirms Active Exploitation of Unified CM Vulnerability CVE-2026-20230
Article Content
- •Cisco's Unified CM vulnerability CVE-2026-20230 is actively being exploited.
- •Attackers can execute SSRF attacks leading to arbitrary file creation on vulnerable systems.
- •Over 200 Cisco Unified CM instances are exposed online, prompting urgent patching.
Cisco has confirmed that attackers are exploiting a vulnerability in its Unified Communications Manager (Unified CM), tracked as CVE-2026-20230, which was patched on June 3, 2026. This vulnerability allows for server-side request forgery (SSRF) attacks through improperly validated HTTP requests, potentially leading to arbitrary file creation on affected systems. The flaw primarily affects systems with the WebDialer service enabled, which is disabled by default. Threat intelligence firm Defused reported active exploitation on June 22, 2026, followed by a technical write-up from SSD Secure. Cisco has urged customers to upgrade to fixed software versions 14SU6 or 15SU5 and provided mitigation measures for those unable to patch immediately. Currently, over 200 Cisco Unified CM instances are exposed online, mainly in Asia and North America. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified this vulnerability as actively exploited in the wild.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Cisco and CVE-2024-20253 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…