HomeSecurityCisco Unified CM: Active exploitation of critical SSRF vulnerability

Cisco Unified CM: Active exploitation of critical SSRF vulnerability

Cisco Unified Communications Manager (Unified CM) is at the center of a new cyber threat, as malicious actors are actively exploiting a critical vulnerability that allows a complete system compromise. The vulnerability, CVE-2026-20230 , with a CVSS score of 8.6 , concerns improper input validation in the WebDialer service and can lead to Server-Side Request Forgery (SSRF) , file writing to the operating system, and ultimately escalation of privileges to root level .

The vulnerability was identified in the WebDialer of Cisco Unified CM and Unified CM SME (Session Management Edition). The problem lies in the system's inability to properly validate URLs provided by the user, allowing an unauthorized, remote attacker to send specially crafted HTTP requests with file:// URIs. Through this technique, the attacker can force the application to write arbitrary files to the underlying operating system, laying the groundwork for a complete server compromise. Importantly, the attack does not require any user interaction or prior authentication.

Cybersecurity firm Defused Cyber ​​reported via X (Twitter) that it observed active exploitation of the vulnerability, with attacks originating from a single source and using an unverified PoC (Proof-of-Concept). The public availability of exploit code significantly lowered the barrier to entry for malicious actors, accelerating attacks.

Cisco Unified CM vulnerability

Cisco Unified CM CVE-2026-20230: Technical Details and Impact

Cisco Unified CM is widely used in enterprise environments for IP telephony, voice communications, and video conferencing. The WebDialer, which is the attack vector, provides click-to-dial functionality and is often enabled in enterprise deployments, although it is disabled by default. SSD Secure Disclosure published additional technical details, describing how the vulnerability allows unauthorized attackers to leverage WebDialer to obtain the target's real hostname and ultimately achieve code execution.

See also: Cisco Unified CM: Vulnerability allows root privileges to be gained

Affected systems include all Cisco Unified CM Release 14 versions prior to 14SU6 and Release 15 versions prior to 15SU5 , as well as Unified CM SME Release 14 prior to 14SU6 . Cisco has released security updates to address the vulnerability, but has not yet officially updated the advisory to reflect the active exploit status.

Cisco Firewall zero-day vulnerability exploited by Interlock ransomware

To check if the WebDialer service is enabled, administrators can log in to the Cisco Unified CM, navigate to Cisco Unified Serviceability from the navigation menu, select Control Center – Feature Services from the Tools menu, and check the status of the Cisco WebDialer Web Service under the CTI Services section. If the status is displayed as “Started,” the service is enabled and the system is exposed.

According to The Hacker News, Cisco PSIRT emphasizes that there is no complete solution without a software update, making the immediate application of security updates absolutely critical. SentinelOne point out that the attack does not require authentication or user interaction, while the scope of the attack extends beyond the vulnerable component, affecting wider system resources.

See also: Cisco: Unified CM has hardcoded SSH root credentials

See also: CVE-2026-20262: Cisco SD-WAN Manager actively exploited

It is worth noting that Cisco announced updates the same week for a moderate severity vulnerability in Catalyst SD-WAN Manager (CVE-2026-20262, CVSS 6.5), which is also being actively exploited.

Article image: CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths - illustration 2

Protection

To protect systems, organizations should immediately apply the 14SU6 or 15SU5 updates , which are the only comprehensive solution. If immediate updates are not possible, it is recommended that the WebDialer service be disabled as a temporary measure. In addition, it is necessary to restrict network access to Cisco Unified CM management interfaces to trusted IP addresses only, monitor for suspicious HTTP requests containing file:// URIs , and audit corporate deployments for systems with WebDialer enabled. The speed with which the vulnerability went from advisory publication to active exploitation underscores the importance of responding promptly to critical communications infrastructure vulnerabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS