Cisco has confirmed that attackers are now exploiting a vulnerability in its Unified Communications Manager (Unified CM) software, which was patched in early June. The vulnerability, identified as CVE-2026-20230, can be exploited remotely by threat actors without privileges, allowing them to conduct low-complexity server-side request forgery (SSRF) attacks.
Vulnerability Details
Unified CM, formerly known as Cisco CallManager, is the central control system for Cisco IP telephony systems, handling call routing, device management, and telephony features. The vulnerability can be exploited by sending a crafted HTTP request, and threat actors can create files on targeted devices using properly constructed file:// payloads.
Exploitation and Response
Cisco's Product Security Incident Response Team (PSIRT) was aware of publicly available proof-of-concept exploit code for CVE-2026-20230 when the security patches were released on June 3. However, it wasn't until June 22 that threat intelligence firm Defused revealed that attackers had begun exploiting the flaw. Another firm, SSD Secure, published a technical write-up on June 23, including a proof-of-concept exploit and explaining how the vulnerability works.
Cisco has finally confirmed that attackers are now exploiting CVE-2026-20230 and is urging customers to secure their systems against ongoing exploitation. The company has shared mitigation measures for admins and security teams who can't immediately install the patched software, advising them to disable the vulnerable WebDialer service until a patch is applied.
Exposed Instances and Previous Flaws
Internet security watchdog Shadowserver is currently tracking over 200 Cisco Unified CM instances exposed online, with most of them located in Asia and North America. Cisco has also patched other Unified CM flaws in recent years, including CVE-2024-20253 and CVE-2025-20309, which enabled threat actors to gain root privileges, and CVE-2026-20045, which was actively exploited as a zero-day to gain remote code execution.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has tagged 93 Cisco vulnerabilities as actively exploited in the wild since November 2021, with six of them being abused in ransomware attacks. This highlights the importance of securing systems against ongoing exploitation and the need for continuous monitoring and testing to prevent attacks.
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
Cisco is strongly recommending that customers upgrade to a fixed software release to remediate the vulnerability. The company has also provided guidance on how to disable the vulnerable WebDialer service until a patch is applied. By taking these steps, customers can help protect their systems against ongoing exploitation of CVE-2026-20230.
Conclusion
The exploitation of CVE-2026-20230 by attackers highlights the importance of prompt patching and securing systems against ongoing exploitation. Cisco's confirmation of active exploitation and the provision of mitigation measures demonstrate the company's commitment to helping customers protect their systems. It is essential for organizations to prioritize security and take proactive measures to prevent attacks and protect their systems and data.
- CVE-2026-20230: Unified Communications Manager vulnerability
- CVE-2024-20253: Unified CM flaw enabling threat actors to gain root privileges
- CVE-2025-20309: Unified CM flaw enabling threat actors to gain root privileges
- CVE-2026-20045: Unified CM flaw actively exploited as a zero-day to gain remote code execution
For more information on how to secure your systems against ongoing exploitation, please refer to the Cisco Unified Communications Manager documentation.
Source: BleepingComputer