Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20045 | Unauthenticated RCE to root in Cisco Unified Communications products CVE-2026-20045 is an unauthenticated, remote command-execution flaw in Cisco Unified Communications Manager (including Session Management Edition), Unified CM IM & Presence Service, Unity Connection, and Webex Calling Dedicated Instance. It is caused by improper validation of user-supplied input in HTTP requests, and is triggered by sending a sequence of crafted HTTP requests to the web-based management interface of an affected device. A successful exploit gives the attacker user-level access to the underlying operating system, which can then be elevated to root — the reason Cisco assigned a Critical Security Impact Rating on top of the 9.8 CVSS score. The affected products are core enterprise call-control and voicemail platforms used by large organizations, plus Cisco-hosted Webex Calling Dedicated Instances. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-01-21 and news reports describe active probing, though no public proof-of-concept code is known and ransomware use is listed as unknown. Do: Upgrade all five affected products (Unified CM, Unified CM SME, Unified CM IM&P, Unity Connection, and Webex Calling Dedicated Instance) to the fixed releases listed in Cisco's advisory, as this data does not specify version numbers. Until patched, restrict access to the web-based management interface to trusted management networks and monitor affected servers for suspicious HTTP request sequences and webshells. Federal agencies must apply vendor mitigations per CISA BOD 22-01 guidance or discontinue use, following the KEV listing of 2026-01-21. | 9.8 | 4% | KEV |
| large≈ tens of thousands of enterprise deployments, likely on the order of 100,000+ Unified CM/Unity Connection servers, with thousands of management interfaces… | |
| CVE-2026-20230 | SSRF in Cisco Unified Communications Manager Enables Root Escalation An unauthenticated server-side request forgery (SSRF) flaw exists in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME), caused by improper input validation of specific HTTP requests. An attacker triggers it by sending a crafted HTTP request to the device's WebDialer service, which must be enabled for exploitation (it is disabled by default). Successful exploitation lets the attacker write files to the underlying operating system, which can later be used to elevate privileges to root — the reason Cisco assigned a Critical Security Impact Rating despite the 8.6 (High) CVSS base score. Organizations running affected Unified CM or Unified CM SME deployments, particularly those with WebDialer enabled and reachable from untrusted networks, are exposed. The flaw is being exploited in the wild: public exploit references appeared in mid-June 2026, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-25, with EPSS indicating an ~88% probability of exploitation within 30 days. Do: Upgrade affected Unified CM and Unified CM SME deployments to the fixed release cited in Cisco's advisory (specific version not provided in this dataset), prioritizing internet-exposed systems per CISA BOD 26-04 requirements. Confirm whether the WebDialer service is enabled and disable it if unused, or restrict network access to it. Check device logs for crafted HTTP requests hitting WebDialer endpoints and unexpected file writes on the underlying OS that could indicate prior exploitation. | 8.6 | 88% | KEV PoC |
| largetens of thousands of internet-exposed Unified CM/SME systems, with the directly exploitable subset smaller because WebDialer must be enabled |
Full article406 words · extracted from helpnetsecurity.com · click to collapse
CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server.
“Our honeypots are seeing automated sweeps dropping webshells, all via Tor,” threat intelligence firm Defused warned today, after observing initial attacks over the weekend.
“The observed chain abuses the WebDialer SSRF to deploy a rogue Apache Axis service, uses that service to write a first-stage JSP file-writer, then drops a second-stage command-execution shell under /platform-services/axis2-web/.”
The vulnerability
Cisco Unified Communications Manager is an enterprise-grade IP telephony and call processing platform. It’s typically deployed as a virtual machine, commonly on Cisco UCS servers running VMware ESXi.
CVE-2026-20230 was reported to Cisco by an independent security researcher working with SSD Secure Disclosure.
It stems from improper input validation for specific HTTP requests, and can be triggered by unauthenticated, remote attackers by sending a specially crafted HTTP request to a vulnerable instance.
“A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root, Cisco said on June 3, 2026, when it revealed the existence of the flaw and released patches for it.
At the time, the vendor confirmed the existence of a proof-of-concept (PoC) exploit for CVE-2026-20230, but said that they were “not aware of any malicious use of the vulnerability.”
A PoC is now public
The PoC they mentioned was likely the one published on Tuesday by the SSD Secure Disclosure technical team.
Knowing the target system’s hostname is a pre-requisite for leveraging the exploit, but that can easily be achieved by accessing a specific URL, they noted.
With the PoC now public, exploitation attempts by other threat actors are likely.
Earlier this year, attackers exploited CVE-2026-20045, a code injection vulnerability in Cisco enterprise communications products (including Unified Communications Manager), in zero-day attacks.
Customers who haven’t upgraded or aren’t able to upgrade to a fixed Cisco Unified Communications Manager or Cisco Unified Communications Manager Session Management Edition version are advised to mitigate the risk of exploitation by disabling the vulnerable WebDialer service.
UPDATE (June 26, 2026, 05:35 a.m. ET):
CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities catalog and ordered US civilian federal government agencies to address it by June 28, 2026.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/06/24/cisco-unified-cm-flaw-exploited-to-drop-webshells-cve-2026-20230/