Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Hackers Exploiting Cisco Unified CM Vulnerability

Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June.

Cisco vulnerability exploited

A recently patched vulnerability affecting Cisco’s Unified Communications Manager (Unified CM) product is being exploited in attacks, according to exploit intelligence firm Defused.

Cisco announced patches for the vulnerability, tracked as CVE-2026-20230, on June 3. The company said the critical security hole can be exploited by an unauthenticated, remote attacker to conduct SSRF attacks, write arbitrary files to the underlying operating system, and escalate privileges to root. Exploitation requires enabling the WebDialer service, which is disabled by default.

When it announced fixes, Cisco noted that a PoC exploit had been available, but said it was not aware of any in-the-wild exploitation. 

Defused said it saw evidence of exploitation over the weekend, noting, “This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys.”

Defused recently also reported seeing the exploitation of three Fortinet product vulnerabilities. 

Shortly after the security firm announced seeing attacks exploiting CVE-2026-20230, SSD Secure Disclosure, which Cisco credited with reporting the vulnerability, published technical details and PoC code showing how the flaw can be leveraged by an unauthenticated attacker for remote code execution. 

Advertisement. Scroll to continue reading.

Cisco has yet to confirm exploitation in its advisory. SecurityWeek has reached out to the tech giant to find out whether it’s aware of the attacks exploiting CVE-2026-20230.

Unified CM is Cisco’s flagship on-premises call control and session management platform. It serves as the core infrastructure for enterprise voice, video, and unified communications. Given that the product is used by large enterprises, CVE-2026-20230 can be highly valuable to both profit-driven cybercriminals and state-sponsored threat actors.

CVE-2026-20230 has yet to be added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, and there do not appear to be other reports of exploitation. 

This is the second Cisco Unified CM vulnerability exploited in 2026. The first was CVE-2026-20045, which threat actors targeted as a zero-day.

Cisco’s SD-WAN products have been the most targeted this year, with eight vulnerabilities exploited to date. 

UPDATE: A Cisco spokesperson provided the following statement to SecurityWeek:


“On June 3, Cisco published a security advisory disclosing a vulnerability in Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition. As of June 24, 2026, Cisco PSIRT is not aware of any malicious use of the vulnerability. We strongly urge customers to upgrade to available fixed software releases that address this vulnerability. Please refer to the security advisory for additional guidance.”

Related: Critical Command Execution Vulnerability Patched in Cisco ISE

Related: Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

Related: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.