Attackers have begun actively exploiting a critical flaw in Cisco Unified Communications Manager (CUCM) to gain root access on vulnerable systems. The attacks appear to have begun less than 24 hours after researchers at SSD Secure Disclosure this week released proof-of-concept code (PoC) along with a full exploit chain for the vulnerability. The vulnerability, tracked as CVE-2026-20230, is an input validation flaw that allows an unauthenticated remote attacker to perform server-side request forgery (SSRF) against affected devices and escalate privileges to root. It impacts Cisco Unified CM and Unified CM SME deployments where the WebDialer service is enabled, allowing users to place calls directly from a Web browser. The service is disabled by default. Cisco released fixed versions of the affected software June 3 and urged organizations to treat CVE-2026-20230 as a critical vulnerability rather than as a high-severity flaw, as its CVSS score of 8.6 might otherwise suggest. CUCM is a central communications management platform that allows organizations to manage a complete range of voice, video, and messaging services. Cisco claims some 30 million users use the platform globally. CVE-2026-20230 is an SSRF vulnerability, a collection of flaws that give attackers a way to trick a server into sending HTTP requests to arbitrary internal or external resources. On communications platforms like CUCM, such bugs can be especially dangerous because they can provide a path to management a...
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
Dark Reading
·Jai Vijayan
·Published Jun 25, 2026
·Updated
Affected Software
2 affected components
Cisco Unified Communications Manager (CUCM)
Cisco Unified Communications Manager (CUCM) SME
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the rapid exploitation of a critical flaw in Cisco Unified Communications Manager (CUCM) that allows attackers to gain root access on affected systems.
2
What security implications are discussed?
The article highlights the risk of unauthorized root access to Cisco CUCM systems, which can lead to severe security breaches.
3
What products or software are affected?
The affected products include Cisco Unified Communications Manager (CUCM) and Cisco Unified Communications Manager SME.
4
How quickly did attackers begin exploiting the identified flaw?
Attackers began exploiting the flaw in less than 24 hours after proof-of-concept code was released.
5
What should organizations using Cisco CUCM do in response to this threat?
Organizations should urgently apply security patches or updates provided by Cisco to mitigate the risk associated with the exploited vulnerability.