Related Threat Clusters
-
CISA Alerts on Exploited Cisco Unified CM Zero-Day Vulnerability CVE-2026-20045
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of a zero-day remote code execution vulnerability in Cisco Unified Communications products,…
3 articles · Updated January 22, 2026 -
Cisco Patches Critical Zero-Day in Unified Communications and Webex Calling
Cisco has addressed a critical zero-day remote code execution vulnerability (CVE-2026-20045) in its Unified Communications and Webex Calling platforms. This flaw, which has a CVSS score of 8.2, is actively exploited by…
2 articles · Updated January 23, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Cisco Issues Warning for Critical Zero-Day Vulnerability in Unified Communications
Cisco has disclosed a critical zero-day remote code execution vulnerability, CVE-2026-20045, affecting multiple Unified Communications products. This flaw allows unauthenticated attackers to execute arbitrary commands…
4 articles · Updated January 22, 2026 -
Cisco Unified CM Remote Code Execution Vulnerability (CVE-2026-20045)
A remote code execution vulnerability, identified as CVE-2026-20045, affects Cisco Unity Connection and Cisco Webex Calling Dedicated Instance. The issue arises from improper handling of input, allowing attackers to…
1 article · Updated January 28, 2026 -
Cisco Confirms Active Exploitation of Unified CM Vulnerability CVE-2026-20230
Cisco has confirmed that attackers are exploiting a vulnerability in its Unified Communications Manager (Unified CM), tracked as CVE-2026-20230, which was patched on June 3, 2026. This vulnerability allows for…
2 articles · Updated July 2, 2026 -
Critical SSRF Vulnerability in Cisco Unified CM Exposes Enterprises to Root Access
Cisco disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (CVE-2026-20230) on June 3, 2026. This flaw allows attackers with network access to write arbitrary files…
8 articles · Updated June 4, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Critical Remote Auth Bypass in GNU telnetd (CVE-2026-24061)
CVE-2026-24061 is a remote authentication bypass vulnerability in GNU InetUtils telnetd, affecting versions 1.9.3 through 2.7. An unauthenticated attacker can exploit this flaw by supplying a specially crafted USER…
7 articles · Updated January 29, 2026 -
Cybercrime Groups Roasted: A New Approach to Threat Awareness
Cybercrime crews are often portrayed as formidable entities, but industry leaders are advocating for a shift in narrative. Former CISA head Jen Easterly and Trellix VP John Fokker emphasize that these actors are merely…
2 articles · Updated April 5, 2026
Recent Intelligence Reports
- Cisco finally confirms attackers exploiting Unified CM flaw — Bleepingcomputer · July 2, 2026
- Cisco Unified Communications flaw exploited by hackers — Computing · June 25, 2026
- Cisco Unified CM CVE-2026-20230: Webshell Drops Confirmed, Patch Alone Won't Evict Attackers — Techtimes · June 24, 2026
- Cisco Unified CM SSRF Flaw CVE-2026-20230: Public Exploit Code Opens Path to Root — Techtimes · June 4, 2026
- Cisco warns of critical Unified CM flaw with PoC exploit code — Bleepingcomputer · June 4, 2026
- Cisco warns of critical Unified CM flaw with PoC exploit code — Bleepingcomputer · June 4, 2026
- Don't glamorize cybercrims, roast them instead — Theregister · April 5, 2026
- Researchers didn’t want to glamorize cybercrims. So they roasted them — Theregister · April 5, 2026