Network Security

Hackers Exploiting Cisco Unified CM Vulnerability

Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June.

Cisco vulnerability exploited

A recently patched vulnerability affecting Cisco’s Unified Communications Manager (Unified CM) product is being exploited in attacks, according to exploit intelligence firm Defused.

Cisco announced patches for the vulnerability, tracked as CVE-2026-20230, on June 3. The company said the critical security hole can be exploited by an unauthenticated, remote attacker to conduct SSRF attacks, write arbitrary files to the underlying operating system, and escalate privileges to root. Exploitation requires enabling the WebDialer service, which is disabled by default.

When it announced fixes, Cisco noted that a PoC exploit had been available, but said it was not aware of any in-the-wild exploitation. 

Defused said it saw evidence of exploitation over the weekend, noting, “This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys.”

Defused recently also reported seeing the exploitation of three Fortinet product vulnerabilities. 

Shortly after the security firm announced seeing attacks exploiting CVE-2026-20230, SSD Secure Disclosure, which Cisco credited with reporting the vulnerability, published technical details and PoC code showing how the flaw can be leveraged by an unauthenticated attacker for remote code execution. 

Advertisement. Scroll to continue reading.

Cisco has yet to confirm exploitation in its advisory. SecurityWeek has reached out to the tech giant to find out whether it’s aware of the attacks exploiting CVE-2026-20230.

Unified CM is Cisco’s flagship on-premises call control and session management platform. It serves as the core infrastructure for enterprise voice, video, and unified communications. Given that the product is used by large enterprises, CVE-2026-20230 can be highly valuable to both profit-driven cybercriminals and state-sponsored threat actors.

CVE-2026-20230 has yet to be added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, and there do not appear to be other reports of exploitation. 

This is the second Cisco Unified CM vulnerability exploited in 2026. The first was CVE-2026-20045, which threat actors targeted as a zero-day.

Cisco’s SD-WAN products have been the most targeted this year, with eight vulnerabilities exploited to date. 

UPDATE: A Cisco spokesperson provided the following statement to SecurityWeek:


“On June 3, Cisco published a security advisory disclosing a vulnerability in Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition. As of June 24, 2026, Cisco PSIRT is not aware of any malicious use of the vulnerability. We strongly urge customers to upgrade to available fixed software releases that address this vulnerability. Please refer to the security advisory for additional guidance.”

Related: Critical Command Execution Vulnerability Patched in Cisco ISE

Related: Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

Related: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

Related Content

Vulnerabilities

Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.

Vulnerabilities

The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Vulnerabilities

The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. 

Artificial Intelligence

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.

Vulnerabilities

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.

Vulnerabilities

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version