Cisco disclosed and patched CVE-2026-20230, a high-severity server-side request forgery flaw in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) WebDialer that can let an unauthenticated attacker write arbitrary files via crafted file:// requests and escalate privileges to root. The issue affects deployments where WebDialer is enabled; although the feature is disabled by default, it is commonly used in enterprise VoIP environments. Cisco issued fixes in early June, including Unified CM 14SU6, while an interim COP patch was made available for release 15 pending a broader 15SU5 update.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities catalog on 2026-06-25 and set a remediation due date of 2026-06-28. The listing reflected the vulnerability's active exploitation status and elevated urgency for remediation.
Public proof-of-concept code and technical details for CVE-2026-20230 were published, increasing the likelihood of broader exploitation. The source content does not provide a specific date for this publication.
Defused observed active exploitation of CVE-2026-20230 on June 20-21, 2026, apparently originating from a single IP address. The activity included reconnaissance attempts to create /tmp/cve-2026-20230-test.txt on vulnerable Cisco Unified CM systems.
Cisco released fixes for the high-severity SSRF vulnerability CVE-2026-20230 in Unified CM and Unified CM SME WebDialer on June 3, 2026. The update included Unified CM 14SU6, while an interim COP patch for release 15 was pending ahead of full 15SU5 planned for September 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcevulnerability.circl.lu
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.