• News/
  • darkreading-20260625215434

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

Dark Reading
·
Jai Vijayan
·
Published Jun 25, 2026
·
Updated

Attackers have begun actively exploiting a critical flaw in Cisco Unified Communications Manager (CUCM) to gain root access on vulnerable systems. The attacks appear to have begun less than 24 hours after researchers at SSD Secure Disclosure this week released proof-of-concept code (PoC) along with a full exploit chain for the vulnerability. The vulnerability, tracked as CVE-2026-20230, is an input validation flaw that allows an unauthenticated remote attacker to perform server-side request forgery (SSRF) against affected devices and escalate privileges to root. It impacts Cisco Unified CM and Unified CM SME deployments where the WebDialer service is enabled, allowing users to place calls directly from a Web browser. The service is disabled by default. Cisco released fixed versions of the affected software June 3 and urged organizations to treat CVE-2026-20230 as a critical vulnerability rather than as a high-severity flaw, as its CVSS score of 8.6 might otherwise suggest. CUCM is a central communications management platform that allows organizations to manage a complete range of voice, video, and messaging services. Cisco claims some 30 million users use the platform globally. CVE-2026-20230 is an SSRF vulnerability, a collection of flaws that give attackers a way to trick a server into sending HTTP requests to arbitrary internal or external resources. On communications platforms like CUCM, such bugs can be especially dangerous because they can provide a path to management a...

Read full article

Affected Software

2 affected components
Cisco Unified Communications Manager (CUCM)
Cisco Unified Communications Manager (CUCM) SME

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the rapid exploitation of a critical flaw in Cisco Unified Communications Manager (CUCM) that allows attackers to gain root access on affected systems.

2

What security implications are discussed?

The article highlights the risk of unauthorized root access to Cisco CUCM systems, which can lead to severe security breaches.

3

What products or software are affected?

The affected products include Cisco Unified Communications Manager (CUCM) and Cisco Unified Communications Manager SME.

4

How quickly did attackers begin exploiting the identified flaw?

Attackers began exploiting the flaw in less than 24 hours after proof-of-concept code was released.

5

What should organizations using Cisco CUCM do in response to this threat?

Organizations should urgently apply security patches or updates provided by Cisco to mitigate the risk associated with the exploited vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203