Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities

Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities

First seen 23 Jun 2026, 23:47 UTC CybersecuritynewsSecurityaffairs.CoButtondownScworld 83% similarity 86.0
Share:

Article Content

Browse articles
ThreatCluster

Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate threat to organizations using the Unified Communications Manager Server. Meanwhile, the Samsung KNOX flaw, an eight-year-old use-after-free vulnerability, affects millions of Galaxy devices, allowing potential kernel-level attacks. Both vulnerabilities have been linked to significant risks, including data breaches and device takeovers. The Cisco vulnerability was published on June 3, 2026, while Samsung's flaw was patched in January 2026. Organizations are urged to apply necessary patches and monitor for indicators of compromise (IOCs) related to these vulnerabilities. The threat landscape remains critical with ongoing AI supply chain threats and other data breaches reported.

Key Points: • CVE-2026-20230 in Cisco Unified CM is actively exploited, posing immediate risks. • CVE-2026-20971 in Samsung KNOX affects millions of devices, allowing kernel attacks. • Organizations must apply patches and monitor for IOCs related to these vulnerabilities.

ThreatCluster AI

Timeline

2026-01-09
CVE-2026-20971 published
Samsung disclosed a critical use-after-free vulnerability in KNOX affecting Galaxy devices.
Scworld
2026-06-03
CVE-2026-20230 published
Cisco disclosed a high-severity SSRF vulnerability in Unified CM, impacting server security.
Buttondown
2026-06-05
First public PoC for CVE-2026-20230
Proof of concept for the Cisco vulnerability was released, increasing exploitation risk.
Buttondown
Recent
Ongoing exploitation reported
Active exploitation of both Cisco and Samsung vulnerabilities has been confirmed, affecting numerous organizations.
Buttondown

Community

Browse all →