Cisco Unified Communications Vulnerability Actively Exploited by Hackers

Cisco Unified Communications Vulnerability Actively Exploited by Hackers

First seen 25 Jun 2026, 20:01 UTC Computingwww.cisco.com 74% similarity 72.9
Share:

Article Content

Browse articles
ThreatCluster

A critical security flaw in Cisco's Unified Communications platforms, identified as CVE-2026-20230, is being actively exploited by hackers. The vulnerability affects Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME) due to improper validation of HTTP requests. This flaw allows unauthenticated attackers to conduct server-side request forgery (SSRF) attacks, potentially leading to privilege escalation and root access. Cisco rated the vulnerability with a severity score of 8.6 out of 10 and released patches on June 3, 2026. Following the disclosure, threat intelligence firm Defused Cyber reported active exploitation attempts, with attackers using crafted file:// requests to test vulnerable systems. The WebDialer service must be enabled for exploitation, but it is disabled by default in many deployments. Organizations are advised to disable the WebDialer service until patches can be applied. Cisco has not yet updated its advisory to reflect the active exploitation status.

Key Points: • CVE-2026-20230 is a critical vulnerability in Cisco Unified CM and SME. • Active exploitation is confirmed, with attackers using crafted HTTP requests. • Organizations should disable the WebDialer service until patches are applied.

ThreatCluster AI

Timeline

2026-01-21
CVE-2026-20045 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-25
CVE-2026-20127 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
CVE-2026-20230 published
Cisco disclosed a critical vulnerability affecting Unified CM and SME due to improper HTTP request validation.
Computing
2026-06-15
Security updates released
Cisco released patches for the vulnerability in Unified CM and SME to mitigate risks associated with CVE-2026-20230.
Cisco
2026-06-15
CVE-2026-20262 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-25
Active exploitation detected
Defused Cyber reported hackers exploiting CVE-2026-20230, using crafted file:// requests to test vulnerabilities.
Computing

Community

Browse all →