securityaffairs.com 6/24/2026, 2:10:49 PM · external

Cisco CUCM CVE-2026-20230 SSRF flaw lets attackers gain root

Cisco CUCM CVE-2026-20230 SSRF flaw lets attackers gain root
Developing story vulnerability 8 articles tracked
Cisco Unified CM SSRF flaw (CVE-2026-20230) allows remote root access
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses a critical vulnerability in Cisco Unified Communications Manager (CVE-2026-20230), which is being actively exploited. The flaw, with a CVSS score of 8.6, allows unauthenticated remote attackers to carry out server-side request forgery (SSRF) attacks, potentially leading to root access. Cisco has advised disabling the WebDialer service to mitigate risks until a patch is released, with initial fixed releases provided for versions 14 and 15 of the software.

Despite the public availability of proof-of-concept (PoC) exploit code, Cisco's PSIRT has not confirmed any active exploitation in the wild, although recent reports from cybersecurity researchers indicate that such exploitation is occurring.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline