Cisco Unified CM CVE-2026-20230 Under Active Exploitation with Webshells Dropped

Cisco Unified CM CVE-2026-20230 Under Active Exploitation with Webshells Dropped

11h ago CybersecuritynewsFeeds.4SysopsGbhackersCsoonlineFeeds2.Feedburner+5 85% similarity 78.0
Share:

Article Content

Browse articles
ThreatCluster

Cisco Unified Communications Manager (Unified CM) is facing active exploitation of a critical vulnerability, CVE-2026-20230, which allows unauthenticated attackers to execute server-side request forgery (SSRF) attacks. The flaw, stemming from improper input validation in HTTP requests, enables attackers to write files to the underlying operating system and potentially gain root access. Threat intelligence firm Defused reported automated attacks deploying multi-stage command-execution webshells, confirmed on June 24, 2026. The vulnerability has been known since Cisco's patch release on June 3, 2026, but many systems remain exposed due to the WebDialer service being enabled. Affected versions include Unified CM 14.x prior to 14SU6 and 15.x prior to 15SU5. Cisco has advised disabling the WebDialer service as a mitigation step until patches can be applied. The situation is urgent as the attacks are ongoing and exploit a critical flaw in widely used enterprise telephony systems.

Key Points: • CVE-2026-20230 allows unauthenticated SSRF attacks and root access on Cisco Unified CM. • Active exploitation confirmed with webshells being deployed via automated Tor-routed sweeps. • Organizations are urged to disable WebDialer service until patches are applied to mitigate risk.

ThreatCluster AI

Timeline

2019-05-01
CVE-2019-0227 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-21
CVE-2026-20045 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
CVE-2026-20230 published and patched
Cisco disclosed a critical SSRF vulnerability affecting Unified CM, providing patches for affected versions.
Techtimes
2026-06-05
First public PoC released
Proof-of-concept exploit code for CVE-2026-20230 was made public, increasing the risk of exploitation.
Mallory.Ai
2026-06-21
Initial attacks observed
Defused reported reconnaissance probes targeting Cisco Unified CM systems over the weekend.
Csoonline
2026-06-24
Active exploitation confirmed
Automated sweeps deploying webshells were confirmed, indicating ongoing exploitation of the vulnerability.
Feeds2.Feedburner

Community

Browse all →