Cisco Unified CM Flaw Exploited After PoC Reveals File
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20230 | SSRF in Cisco Unified Communications Manager Enables Root Escalation An unauthenticated server-side request forgery (SSRF) flaw exists in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME), caused by improper input validation of specific HTTP requests. An attacker triggers it by sending a crafted HTTP request to the device's WebDialer service, which must be enabled for exploitation (it is disabled by default). Successful exploitation lets the attacker write files to the underlying operating system, which can later be used to elevate privileges to root — the reason Cisco assigned a Critical Security Impact Rating despite the 8.6 (High) CVSS base score. Organizations running affected Unified CM or Unified CM SME deployments, particularly those with WebDialer enabled and reachable from untrusted networks, are exposed. The flaw is being exploited in the wild: public exploit references appeared in mid-June 2026, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-25, with EPSS indicating an ~88% probability of exploitation within 30 days. Do: Upgrade affected Unified CM and Unified CM SME deployments to the fixed release cited in Cisco's advisory (specific version not provided in this dataset), prioritizing internet-exposed systems per CISA BOD 26-04 requirements. Confirm whether the WebDialer service is enabled and disable it if unused, or restrict network access to it. Check device logs for crafted HTTP requests hitting WebDialer endpoints and unexpected file writes on the underlying OS that could indicate prior exploitation. | 8.6 | 88% | KEV PoC |
| largetens of thousands of internet-exposed Unified CM/SME systems, with the directly exploitable subset smaller because WebDialer must be enabled | |
| CVE-2026-20262 | Authenticated Path Traversal File Overwrite in Cisco Catalyst SD-WAN Manager CVE-2026-20262 is a directory/path traversal vulnerability (CWE-22) in Cisco Catalyst SD-WAN Manager, the central management component of Cisco's enterprise SD-WAN solution. An authenticated, remote attacker can supply crafted input containing traversal sequences that escape the intended directory, allowing the attacker to create a new file or overwrite any file on the affected system's filesystem. Overwriting arbitrary files can enable configuration tampering, persistence, or privilege escalation on the management appliance depending on which file is targeted. Any organization running Cisco Catalyst SD-WAN Manager is affected, with greatest risk where the management interface is reachable by broad user populations or from the internet. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-15, indicating exploitation in the wild; no public proof-of-concept is known, ransomware association is unknown, CVSS is not yet scored, and EPSS assigns a 28.2% probability of exploitation within 30 days (98th percentile). Do: Apply the fixed release per Cisco's advisory (specific fixed versions are not provided in this data set, so consult Cisco's security notice) and follow CISA's KEV required action, including BOD 26-04 timelines for federal agencies and cloud service use. Until patched, restrict access to the SD-WAN Manager management interface to trusted management networks, enforce strong authentication, and audit the filesystem for unexpectedly created or recently modified files that could indicate exploitation. Evaluate each instance's internet exposure and prioritize internet-reachable management appliances for immediate remediation. | 6.5 | 28% | KEV |
| largetens of thousands of enterprise management deployments (roughly 10k-100k systems) |
Full article499 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 24, 2026Vulnerability / Network Security
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).
The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device," Cisco said in an advisory released earlier this month. "A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root."
In a post shared on X earlier this week, Defused Cyber said it observed active exploitation of the vulnerability in attacks. "This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys," it noted.
However, for successful exploitation to occur, the WebDialer service must be enabled. It's disabled by default. To check if the WebDialer is enabled, users can complete the following steps -
- Log in to the Cisco Unified CM Administration interface
- From the Navigation menu, choose Cisco Unified Serviceability and click Go
- From the Tools menu, choose Control Center - Feature Services
- In the CTI Services section of the page, check whether the current status of the Cisco WebDialer Web Service is Started or Not Running
- If the status is Started, WebDialer is enabled
The vulnerability has been patched in Unified CM and Unified CM SME versions 14SU6 and 15SU5. If immediate patching is not an option, it's advised to disable the WebDialer service until a fix can be applied.
SSD Secure Disclosure has since published additional technical specifics of CVE-2026-20230, describing it as a flaw that allows unauthenticated attackers to arbitrarily write files in the server by leveraging the Webdialer component to obtain the true hostname of the target and ultimately achieve code execution.
Cisco has yet to update the advisory to reflect the exploitation status. Last week, the network security company released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager (CVE-2026-20262, CVSS score: 6.5) that has come under active exploitation in the wild.
Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on June 25, 2026, added CVE-2026-20230 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 28, 2026.
As of July 1, 2026, Cisco updated its advisory to confirm that it became aware of active exploitation of the vulnerability last month, urging customers to upgrade to a fixed software release to remediate the issue.
(The story was updated after publication on July 2, 2026, to reflect the latest developments.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html