Critical SSRF Vulnerability in Cisco Unified CM Exposes Enterprises to Root Access

Critical SSRF Vulnerability in Cisco Unified CM Exposes Enterprises to Root Access

4 Jun 2026 GbhackersBleepingcomputerTechtimesdeveloper.cisco.comCsa.Sg+3 84% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

Cisco disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (CVE-2026-20230) on June 3, 2026. This flaw allows attackers with network access to write arbitrary files to the operating system, potentially escalating privileges to root. A proof-of-concept exploit code was released shortly after the disclosure, increasing the urgency for affected organizations. The vulnerability impacts systems where the WebDialer service is enabled, which is often the case in enterprise environments. Cisco has assigned a Critical Security Impact Rating to this vulnerability, despite a CVSS score of 8.6. Administrators are advised to check the status of the WebDialer service and apply security updates promptly. Currently, there is no evidence of active exploitation, but the availability of PoC code raises concerns about potential attacks. Organizations are encouraged to disable the WebDialer service until patches are applied.

Key Points: • CVE-2026-20230 allows root access via SSRF in Cisco Unified CM if WebDialer is enabled. • Public exploit code for this vulnerability was released shortly after Cisco's disclosure. • Cisco recommends immediate updates and disabling the WebDialer service as a precaution.

ThreatCluster AI

Timeline

2024-01-26
CVE-2024-20253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-21
CVE-2026-20045 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
CVE-2026-20230 published
Cisco disclosed a critical SSRF vulnerability in Unified Communications Manager, allowing root access.
Techtimes
2026-06-04
Public PoC exploit code released
Proof-of-concept exploit code for CVE-2026-20230 became publicly available, raising risks for enterprises.
Gbhackers
2026-06-04
Cisco issues security updates
Cisco released updates to patch the critical vulnerability and recommended immediate action for affected users.
Bleepingcomputer
2026-06-05
Security advisory issued
Cisco's advisory emphasized the critical nature of the vulnerability and the need for immediate updates.
Csa.Sg

Community

Browse all →