CVE-2026-20230
published 2026-06-03CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could…
PriorityP191high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-28
Exploited in the wild
EPSS
80.88%
99.6th percentile
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.
Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 14.0 < 14su6 | 14su6 |
| cisco | unified_communications_manager | 15.0 – 15su4a | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted HTTP requests targeting the Cisco Unified CM WebDialer component containing file:// URI schemes, which are used to trigger the SSRF file-write primitive. ↗
- →Monitor for creation of unexpected files under /tmp/ on Cisco Unified CM hosts, particularly files matching the pattern /tmp/cve-2026-20230-test.txt, as reconnaissance-phase exploitation attempts write text files to this path. ↗
- →Alert on exploitation attempts originating from a single source IP conducting repeated HTTP requests with file:// payloads against Cisco Unified CM endpoints; current observed campaign uses a single source IP. ↗
- →Check whether the Cisco WebDialer Web Service status is 'Started' in the CTI Services section of Control Center - Feature Services; exploitation requires WebDialer to be enabled. ↗
- →Monitor for attacker pre-exploitation hostname enumeration activity against the Webdialer component, as exploitation requires the attacker to first obtain the target system's hostname before carrying out the file-write attack. ↗
- →Watch for webshell drops following file-write exploitation of CVE-2026-20230; post-reconnaissance exploitation is expected to escalate to webshell deployment and root privilege escalation. ↗
- ·Exploitation of CVE-2026-20230 requires the WebDialer service to be enabled on the target Cisco Unified CM instance; WebDialer is disabled by default, significantly limiting the attack surface. ↗
- ·Patched versions are Cisco Unified CM and Unified CM SME 14SU6 and 15SU5; if patching is not immediately possible, disabling the WebDialer service is the recommended interim mitigation. ↗
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
vulncheck8.6HIGH
cisa8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
cisa·2026-06-25·CVSS 8.6
CVE-2026-20230 [HIGH] CWE-918 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Vulnerability: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
Affected: Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services
VulDB
Cisco Unified Communications Manager WebDialer Service server-side request forgery (cisco-sa-cucm-ssrf-cXPnHcW)
vuldb·2026-06-03·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco Unified Communications Manager WebDialer Service server-side request forgery (cisco-sa-cucm-ssrf-cXPnHcW)
A vulnerability categorized as critical has been discovered in Cisco Unified Communications Manager. This issue affects some unknown processing of the component WebDialer Service. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-20230. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacke
ghsa_unreviewed·2026-06-03
CVE-2026-20230 [HIGH] CWE-918 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacke
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability co
VulnCheck
Cisco unified_communications_manager Server-Side Request Forgery (SSRF)
vulncheck·2026·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco unified_communications_manager Server-Side Request Forgery (SSRF)
Cisco unified_communications_manager Server-Side Request Forgery (SSRF)
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.
Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the sc
No detection rules found.
No public exploits indexed.
Bleepingcomputer
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
blogs_bleepingcomputer·2026-06-26·CVSS 9.8
CVE-2026-20230 [CRITICAL] CISA sets urgent deadline to fix Cisco flaw exploited in attacks
## CISA sets urgent deadline to fix Cisco flaw exploited in attacks
## Bill Toulas
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited.
Identified as CVE-2026-20230, the security issue is server-side request forgery (SSRF) and has been added to the agency's catalog of Known Exploited Vulnerabilities (KEV).
Per Binding Operational Directive (BOD) 26-04 , the remediation is deemed urgent and must addressed by Sunday, June 28.
Cisco marked CVE-2026-20230 with critical severity and released a patch on June 3, warning that it could be exploited remotely and without authentication via specially crafted HTTP requests.
At the time, the
Hackernews
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
blogs_hackernews·2026-06-24·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).
The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
"An attacker could exploit this vulnerability by sending a crafted HTTP
Bleepingcomputer
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
blogs_bleepingcomputer·2026-06-23·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
## Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
## Lawrence Abrams
A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks.
Cisco released security updates for the CVE-2026-20230 flaw on June 3, warning that exploitation could give attackers root privileges on the device.
"A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device," warned Cisco .
"This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this v
Hackernews
⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
blogs_hackernews·2026-06-08·CVSS 8.4
CVE-2025-48595 [HIGH] ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked.
A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes showed up again. And while everyone chased the loud stuff, quieter attackers sat in inboxes for months, reading mail and stealing it bit by bit.
Lots to cover. Grab coffee. Read up.
## ⚡ Threat of the Week
Miasma Worm Hits 73 Microsoft GitHub Repositories in Supply Chain
Checkpoint
8th June – Threat Intelligence Report
blogs_checkpoint·2026-06-08
CVE-2025-48595 8th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 1st June, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked exfiltrated data. Analysts assessed that 2.6 million accounts were exposed, including names, emails, government IDs, and health insurance details.
Password manager Dashlane has disclosed an attack
Hackernews
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
blogs_hackernews·2026-06-06·CVSS 10.0
CVE-2026-20245 [CRITICAL] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available
Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked as CVE-2026-20245 , carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -
On-Prem Deployment
Cisco SD-WAN Cloud-Pro
Cisco SD-WAN Cloud (Cisco Managed)
Cisco SD-WAN for Government (FedRAMP)
"A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary co
Hackernews
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
blogs_hackernews·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories
It got stupid again.
The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and come back worse. Cheap hackers get better toys. AI starts breaking real systems. Great.
Read the whole thing before it ruins your week anyway.
Cisco has released fixes to address a high-severity security flaw in Unified Communications Manager (CVE-2026-20230, CVSS score: 8.6) that could allow an unauthe
Bleepingcomputer
Cisco warns of critical Unified CM flaw with PoC exploit code
blogs_bleepingcomputer·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco warns of critical Unified CM flaw with PoC exploit code
## Cisco warns of critical Unified CM flaw with PoC exploit code
## Sergiu Gatlan
Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges.
Cisco Unified CM (formerly known as Cisco CallManager) serves as the central control system for Cisco IP telephony systems, handling device management, call routing, and telephony features.
The vulnerability (tracked as CVE-2026-20230 ) can be exploited remotely by threat actors without privileges in low-complexity server-side request forgery (SSRF) attacks.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating
Hackernews
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
blogs_hackernews·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026-20230 , and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.
The flaw is a server-side request forgery. Unified CM and its Session Management Edition fail to validate certain HTTP requests properly, so a crafted request can push the server into writing arbitrary files onto
2026-06-03
Published
2026-06-25
Added to CISA KEV
Exploited in the wild