VYPR
kevPublished Jun 23, 2026· Updated Jul 2, 2026· 7 sources

Cisco Unified CM SSRF Flaw CVE-2026-20230 Now Actively Exploited in Attacks

Cisco warns that a high-severity SSRF vulnerability in Unified Communications Manager is being actively exploited, urging immediate patching.

Cisco has issued an urgent warning that CVE-2026-20230, a high-severity server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) and Unified CM SME, is now being actively exploited in the wild. The flaw, which carries a CVSS score of 8.6, allows an unauthenticated attacker to send arbitrary requests to internal services, potentially leading to further compromise of the network.

The vulnerability resides in the web-based management interface of Unified CM and Unified CM SME. By sending specially crafted HTTP requests, an attacker can trick the server into making requests to internal systems that would otherwise be inaccessible. This SSRF vector can be used to scan internal networks, access sensitive data, or pivot to other vulnerable services behind the firewall.

Cisco has confirmed that proof-of-concept exploit code is publicly available, and the company is aware of active exploitation attempts targeting unpatched systems. The advisory notes that no workarounds are available, leaving software updates as the only mitigation. Administrators are urged to apply the fixed releases immediately.

The affected products are widely deployed in enterprise telephony and collaboration environments. Unified CM serves as the call-processing component of Cisco's unified communications suite, handling voice, video, and messaging for organizations of all sizes. The SME variant is tailored for service provider environments, extending the attack surface to critical infrastructure.

Cisco has released software updates for all supported versions of Unified CM and Unified CM SME. The patches are available through the Cisco Software Download Center. The company has not yet added this CVE to the CISA Known Exploited Vulnerabilities (KEV) catalog, but given active exploitation, inclusion is likely imminent.

This incident follows a pattern of increasing SSRF vulnerabilities being weaponized by attackers. SSRF flaws are particularly dangerous because they bypass traditional perimeter defenses, allowing attackers to interact with internal systems from the internet. Organizations that have not yet patched should treat this as a critical priority, especially those in sectors like healthcare, finance, and government where Unified CM is common.

Cisco's advisory also reminds customers to verify the integrity of downloaded software and to follow best practices for securing management interfaces, such as restricting access via ACLs and using VPNs for remote administration. As exploitation continues, the window for proactive defense is closing rapidly.

Exploit intelligence firm Defused has now confirmed active exploitation of CVE-2026-20230 over the weekend, observing a single attacker using unvetted proof-of-concept code with file:// write payloads hitting decoy systems. Shortly after Defused's report, SSD Secure Disclosure—credited by Cisco with finding the flaw—published technical details and PoC code demonstrating unauthenticated remote code execution. Cisco has not yet updated its advisory to acknowledge the attacks, and the vulnerability remains absent from CISA’s Known Exploited Vulnerabilities catalog.

Defused Cyber reported observing active exploitation from a single source using an unvetted proof-of-concept that delivers file:// file-write payloads. SSD Secure Disclosure published additional technical details, describing how attackers leverage the WebDialer component to obtain the true hostname and achieve code execution. Cisco has not yet updated its advisory to reflect the exploitation status, but patches are available in Unified CM and Unified CM SME versions 14SU6 and 15SU5.

Threat intelligence firm Defused reported that automated sweeps via Tor are now dropping webshells on vulnerable Cisco Unified CM instances, chaining the WebDialer SSRF to deploy a rogue Apache Axis service, a first-stage JSP file-writer, and a second-stage command-execution shell under /platform-services/axis2-web/. A proof-of-concept exploit published by SSD Secure Disclosure has gone public, and with a target hostname easily obtainable via a specific URL, exploitation attempts by additional threat actors are expected to escalate.

New reports from Defused show that attackers weaponized the public proof-of-concept code for CVE-2026-20230 within 24 hours, hitting decoy systems with a full exploit chain that deploys a rogue Apache Axis service, writes a first-stage JSP file-writer, and drops a second-stage command-execution shell. Horizon3.ai has released a rapid response test for organizations to verify exploitability, while Cisco continues to urge immediate patching or disabling of WebDialer for organizations using Unified CM across healthcare, finance, government, and enterprise environments.

Cisco has now confirmed that the vulnerability, CVE-2026-20230, is being actively exploited in the wild. This confirmation follows the public availability of a proof-of-concept exploit and the observation of exploitation attempts in the past week, underscoring the immediate risk to organizations using Cisco Unified Communications Manager.

Cisco has now officially confirmed that attackers are actively exploiting CVE-2026-20230, a server-side request forgery vulnerability in its Unified Communications Manager software. While initially aware of public exploit code but no active exploitation in early June, Cisco's stance shifted by late June as threat intelligence firms observed exploitation and Cisco's own advisory was updated to reflect the ongoing attacks. The company continues to urge customers to upgrade to patched versions or disable the vulnerable WebDialer service as a mitigation.

Synthesized by Vypr AI