Multiple outlets report that threat actors are exploiting a recently disclosed high-severity vulnerability, CVE-2026-20230, affecting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The flaw is described as improper input validation tied to specific HTTP requests, and it is characterized as a server-side request forgery (SSRF) issue. Sources say the vulnerability can be reached without authentication and remotely, and they cite a CVSS score of 8.6. Bleeping Computer and Help Net Security both state that the weakness is now used in real-world attacks rather than only proof-of-concept activity. Help Net Security adds operational detail from observations by a threat intelligence firm, describing automated activity that drops webshells and leverages an SSRF “WebDialer” chain to deploy a rogue service component (including an Apache Axis-based element) and write first-stage code, leading toward remote code execution on the affected server. The Hacker News notes that a proof-of-concept revealed a file-write path to root, aligning with claims that attackers can progress from the initial SSRF condition to full system compromise.