Cisco patches Cisco Unified CM flaw CVE-2026-20230 that could lead to root access, warns public PoC exists

Cisco released fixes for a serious security flaw in Cisco Unified Communications Manager and Unified Communications Manager Session Management Edition that could let remote attackers gain a path to full control of affected appliances. The bug, CVE-2026-20230, is a server-side request forgery issue caused by improper validation of certain HTTP requests; on systems with the WebDialer service enabled, an unauthenticated attacker can send crafted requests to write files to the underlying operating system and potentially escalate to root. Cisco fixed it in Unified CM and Unified CM SME 14SU6 and plans to include fixes in 15SU5.
Why it matters: Organizations running affected Cisco call-management systems should check whether WebDialer is enabled and apply updates quickly, especially because proof-of-concept exploit code is already public. Even without confirmed in-the-wild exploitation, the flaw could give attackers a foothold that leads to full device compromise.

Sources

Cisco finally confirms attackers exploiting Unified CM flaw
Sergiu Gatlan 2026.07.02 98% relevant
This updates the same underlying event by adding Cisco’s vendor confirmation that CVE-2026-20230 is now being actively exploited, along with the recommendation to upgrade to fixed releases or disable the vulnerable WebDialer service as a mitigation.
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
Ionut Arghire 2026.07.02 97% relevant
This article updates the same CVE-2026-20230 event with the key new fact that Cisco has now confirmed active exploitation in the wild after previously saying it was only aware of public proof-of-concept code.
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Bill Toulas 2026.06.26 96% relevant
This is a direct update to the same CVE-2026-20230 event, adding that CISA has now added the flaw to KEV after active exploitation was observed and ordered federal agencies to patch by June 28.
The hits keep on coming for Cisco vulnerabilities
2026.06.24 95% relevant
This article updates the same Unified Communications Manager event by adding that CVE-2026-20230 is now being exploited in the wild and describing the observed exploitation chain using WebDialer SSRF to deploy rogue Axis services and JSP shells.
Hackers Exploiting Cisco Unified CM Vulnerability
Eduard Kovacs 2026.06.24 96% relevant
This is a direct update to the same CVE-2026-20230 story, adding the key new development that Defused has observed in-the-wild exploitation against decoys after Cisco's June 3 patch, alongside newly published technical details and proof-of-concept code.
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
Lawrence Abrams 2026.06.23 95% relevant
This is a direct update to the same CVE-2026-20230 event, adding that the flaw is now being actively exploited in the wild, that observed attacks used file:// payloads to write test files, and that technical details and a PoC have now been published.
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
info@thehackernews.com (The Hacker News) 2026.06.04 99% relevant
The article appears to cover the same underlying event: Cisco’s patch release for CVE-2026-20230 in Unified Communications Manager and the fact that proof-of-concept exploit code is publicly available.
Cisco warns of critical Unified CM flaw with PoC exploit code
Sergiu Gatlan 2026.06.04 99% relevant
This article is the same underlying event: Cisco's disclosure and patching of CVE-2026-20230 in Unified CM, including that public PoC exploit code exists, the flaw affects systems with WebDialer enabled, and admins can disable WebDialer until updating to fixed releases.
Cisco Warns of Available PoC for Critical Unified CM Vulnerability
Ionut Arghire 2026.06.04 100% relevant
This article establishes a new tracked story by disclosing Cisco's patch release and warning about public exploit code for CVE-2026-20230 in Unified CM/Unified CM SME; it is distinct from the existing Cisco Secure Workload story, which concerns a different product and CVE.
← Back to all stories