CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

June 25, 2026

Threat actors have begun exploiting a critical vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME), tracked as CVE-2026-20230 (CVSS 8.6). The flaw, an improper input validation issue in HTTP request handling, allows unauthenticated remote attackers to perform server-side request forgery (SSRF) attacks and write arbitrary files to the underlying operating system, potentially leading to root privilege escalation.

Active exploitation was reported by Defused Cyber, noting attacks from a single source using an unvetted proof-of-concept (PoC) with file:// payloads. The vulnerability requires the WebDialer service to be enabled (disabled by default). Cisco has released patches in Unified CM and Unified CM SME versions 14SU6 and 15SU5. If patching is not immediately possible, disabling WebDialer is recommended. SSD Secure Disclosure published additional technical details, describing how attackers can leverage the WebDialer component to obtain the target hostname and achieve code execution. Cisco has not yet updated its advisory to reflect active exploitation.

Additionally, Cisco patched a medium-severity flaw in Catalyst SD-WAN Manager (CVE-2026-20262, CVSS 6.5) that is also under active exploitation.

CVEs: CVE-2026-20230, CVE-2026-20262, CVE-2026-11645

Companies: Cisco, Defused Cyber, SSD Secure Disclosure

Products: Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Catalyst SD-WAN Manager, Cisco WebDialer