• News/
  • bleepingcomputer-20260702113525

Cisco finally confirms attackers exploiting Unified CM flaw

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 2, 2026
·
Updated

Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. Unified CM (formerly known as Cisco CallManager) is the central control system for Cisco IP telephony systems, handling call routing, device management, and telephony features. Threat actors without privileges can exploit the vulnerability (CVE-2026-20230) remotely in low-complexity server-side request forgery (SSRF) attacks by sending a crafted HTTP request. Cisco said on June 3, when it released security patches to address this issue, that its Product Security Incident Response Team (PSIRT) was aware of publicly available proof-of-concept exploit code for CVE-2026-20230 but had no evidence of active exploitation. However, roughly three weeks later, on June 22, threat intelligence firm Defused revealed that attackers had begun exploiting the flaw using properly constructed file:// payloads to create files on targeted devices. One day later, SSD Secure also published a technical write-up that included a proof-of-concept exploit and explained how the vulnerability works. BleepingComputer contacted Cisco at the time to ask whether they were also seeing the flaw actively exploited in attacks and whether they could share any IOCs with defenders, but we have yet to receive a response. The company finally confirmed this Wednesday that attackers are now exploiting CVE-2026-20230 and urged customers to secure their systems against ongoing exploitation....

Read full article

Affected Software

1 affected component
Cisco Unified Communications Manager (Unified CM)=14SU6, =15SU5

Frequently Asked Questions

1

What vulnerability is being exploited according to Cisco's confirmation?

Cisco confirmed that attackers are exploiting a vulnerability in the Unified Communications Manager (Unified CM).

2

When was the vulnerability in Cisco Unified CM first patched?

The vulnerability in Cisco Unified CM was first patched in early June 2026.

3

What type of system does Unified CM control?

Unified CM controls Cisco IP telephony systems, managing call routing and device management.

4

What does the term KEV-listed refer to in the context of this vulnerability?

KEV-listed refers to a vulnerability that is included in the Known Exploited Vulnerabilities catalog, indicating it is actively being exploited.

5

When was this security issue first published to the public?

This security issue was published on July 2, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203