Critical Cisco CUCM Flaw Exploited Within 24 Hours of PoC Release

Critical Cisco CUCM Flaw Exploited Within 24 Hours of PoC Release

First seen 25 Jun 2026, 20:01 UTC Computingwww.cisco.comDarkreadinghorizon3.ai 79% similarity 78.0
Share:

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Cisco Unified Communications Manager (CUCM), tracked as CVE-2026-20230, has been actively exploited by attackers less than 24 hours after proof-of-concept (PoC) code was released. The flaw allows unauthenticated remote attackers to perform server-side request forgery (SSRF) and escalate privileges to root. It affects Cisco Unified CM and Unified CM SME deployments where the WebDialer service is enabled, which is disabled by default. Cisco rated the vulnerability as critical with a CVSS score of 8.6 and released patches on June 3. Researchers from Defused observed attacks targeting their decoy CUCM systems shortly after the PoC was made public. The exploit involves sending crafted HTTP requests to the WebDialer service, allowing attackers to write files to the underlying operating system, potentially leading to full administrative control. Organizations are advised to disable the WebDialer service until patches can be applied.

Key Points: • CVE-2026-20230 is a critical SSRF vulnerability in Cisco CUCM exploited within 24 hours of PoC release. • Attackers can gain root access by exploiting the WebDialer service, which is disabled by default. • Cisco has released patches and recommends disabling the WebDialer service as a temporary mitigation.

ThreatCluster AI

Timeline

2026-01-21
CVE-2026-20045 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-25
CVE-2026-20127 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-03
CVE-2026-20230 published
Cisco disclosed a critical SSRF vulnerability in CUCM with a CVSS score of 8.6.
Cisco
2026-06-05
First public PoC released
Proof-of-concept code for CVE-2026-20230 was made public, demonstrating the exploit.
Darkreading
2026-06-15
CVE-2026-20262 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-24
Active exploitation observed
Defused Cyber detected attacks targeting CUCM systems using the newly released PoC.
Darkreading
2026-06-25
CVE added to CISA KEV
CVE-2026-20230 was added to the CISA Known Exploited Vulnerabilities catalog due to active exploitation.
Computing
2026-06-25
Cisco security advisory issued
Cisco released an advisory urging customers to apply patches and disable WebDialer service.
Cisco

Community

Browse all →