CVE Tools

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

SecurityWeekBy Ionut Arghire

Reported exploitedCisco Unified Communications Manager

Our summary

Cisco reports that CVE-2026-20230 has been exploited in the wild in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The issue stems from improper validation of certain HTTP requests and could enable SSRF-style activity that may ultimately allow arbitrary file drops and potential root access. This matters because only devices with the WebDialer service enabled are affected (disabled by default), and Cisco advises upgrading to fixed releases to remediate.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store