HackMyIP
← Back to News
2026-06-24 The Hacker News

Cisco Unified CM CVE-2026-20230 Actively Exploited — Patch Now

VulnerabilityZero-DayIncident Response

Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition, tracked as CVE-2026-20230 with a CVSS score of 8.6. The flaw stems from improper input validation on specific HTTP requests, enabling an unauthenticated, remote attacker to perform server-side request forgery (SSRF) attacks against affected appliances. According to threat intelligence posted on X by Defused Cyber, exploitation has already been observed in the wild using an unvetted public proof-of-concept, with properly formatted `file://` write payloads hitting the firm's deployed decoys.

The attack path hinges on the WebDialer service, which is disabled by default but commonly enabled in enterprise deployments. By sending a crafted HTTP request to the WebDialer endpoint, an attacker can coerce the device into writing arbitrary files to the underlying operating system. SSD Secure Disclosure's technical analysis confirms that those file-write primitives can be chained to obtain the true internal hostname of the target and ultimately achieve root-level code execution, transforming an unauthenticated network request into full system compromise. Organizations that have not yet patched should immediately run a port scanner against their Cisco Unified CM appliances to confirm whether WebDialer ports are reachable from untrusted networks.

Cisco has shipped fixes in Unified CM and Unified CM SME versions 14SU6 and 15SU5 and recommends applying the patch as soon as possible. For environments where immediate patching is not feasible, administrators should disable the WebDialer service via the Cisco Unified Serviceability Control Center — Feature Services panel, then verify the change from the CTI Services section. Because the flaw requires an inbound network path, defenders should also audit perimeter firewall rules and ensure management interfaces are not exposed to the public internet. As a quick hygiene step, run an SSL/TLS checker against any reachable Cisco management interfaces to confirm certificates are valid and properly configured, reducing the attack surface for follow-on exploitation.

Cisco has not yet updated its official advisory to reflect in-the-wild exploitation, but the convergence of a public PoC, active scanning, and a trivial pre-auth path makes this a high-priority remediation item. Security teams should treat any Unified CM appliance running an unpatched build with WebDialer enabled as actively compromised and initiate incident response procedures — including log review for unexpected file writes, anomalous child processes spawned by the WebDialer service, and outbound connections to unfamiliar destinations.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →