Multiple outlets report that threat actors are exploiting a recently disclosed high-severity vulnerability, CVE-2026-20230, affecting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The flaw is described as improper input validation tied to specific HTTP requests, and it is characterized as a server-side request forgery (SSRF) issue. Sources say the vulnerability can be reached without authentication and remotely, and they cite a CVSS score of 8.6. Bleeping Computer and Help Net Security both state that the weakness is now used in real-world attacks rather than only proof-of-concept activity. Help Net Security adds operational detail from observations by a threat intelligence firm, describing automated activity that drops webshells and leverages an SSRF “WebDialer” chain to deploy a rogue service component (including an Apache Axis-based element) and write first-stage code, leading toward remote code execution on the affected server. The Hacker News notes that a proof-of-concept revealed a file-write path to root, aligning with claims that attackers can progress from the initial SSRF condition to full system compromise.
Cisco Unified CM flaw CVE-2026-20230 reportedly exploited to enable remote code execution
Multiple outlets report that threat actors are exploiting a recently disclosed high-severity vulnerability, CVE-2026-20230, affecting Cisco Unified Communications Manager (Unified CM) and Unified Comm...
- CVE-2026-20230 affects Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME).
- The vulnerability is described as an SSRF issue tied to improper input validation for certain HTTP requests.
- Reports state the flaw can be exploited remotely without authentication.
- At least two outlets report active exploitation in the wild, with automated behavior observed soon after disclosure.
- Observed exploitation chains reportedly use the SSRF to deploy webshells and support remote code execution on the underlying server.
CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all via Tor,” threat intelligence firm Defused warned today, after observing initial attacks over the weekend. “The observed chain abuses the WebDialer SSRF to deploy a rogue Apache Axis service, uses that service to write a first-stage … More → The post Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) appeared first on Help Net Security.
2 months agoThreat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote
2 months agoA high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. [...]
2 months ago
Trump’s North Korea outreach sparks doubts over U.S. security reliability in Asia
Donald Trump’s outreach to North Korea’s Kim Jong Un is prompting fresh doubts among Asian partners about the reliabilit...
Iranian warship deters Indian tanker attempting Strait of Hormuz transit
Iranian state media reports that a large Iranian warship confronts an Indian oil tanker as it attempts to transit the so...
Peter Hitchens says he feels relief when trains run late
Peter Hitchens says he now feels a positive reaction when his trains are late, describing moments where he welcomes dela...