Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Unified CM Flaw Exploited by Hackers

Cisco Unified CM Flaw Exploited by Hackers

Posted on June 24, 2026 By CWS

A vulnerability recently patched in Cisco’s Unified Communications Manager (Unified CM) has been actively exploited by hackers, according to updates from cybersecurity firm Defused. The flaw, identified as CVE-2026-20230, was addressed by Cisco on June 3.

Details of the Vulnerability

The security issue, labeled as critical, allows unauthenticated remote attackers to execute server-side request forgery (SSRF) attacks, write arbitrary files, and escalate their privileges to root level. These attacks require the WebDialer service to be enabled, although it is typically disabled by default.

Upon releasing the patch, Cisco acknowledged the availability of a proof-of-concept (PoC) exploit but initially reported no known in-the-wild exploitation. However, recent evidence from Defused suggests otherwise.

Current Exploitation Activities

Defused has identified exploitation attempts occurring over a recent weekend. The firm noted, “We are witnessing exploitation from a single origin deploying an unvetted PoC, with file:// payloads being delivered to our decoys.” This revelation highlights active efforts by attackers to leverage the vulnerability.

In a related development, SSD Secure Disclosure, credited by Cisco for reporting the flaw, released technical details and PoC code that demonstrate how unauthenticated attackers can achieve remote code execution through this vulnerability.

Implications and Industry Response

Unified CM is a core component of Cisco’s enterprise communication infrastructure, used globally for voice and video services. The discovery of CVE-2026-20230’s exploitation underscores the potential risks it poses to large organizations, making it an attractive target for both financially motivated cybercriminals and state-sponsored actors.

Despite the evidence of exploitation, Cisco has not yet confirmed these incidents in their advisories. SecurityWeek has reached out to Cisco for comments on the matter. Additionally, this vulnerability has not been listed in CISA’s Known Exploited Vulnerabilities catalog, and no other reports have surfaced regarding its exploitation.

This situation marks the second time in 2026 that a vulnerability in Cisco Unified CM has been exploited. The first instance involved CVE-2026-20045, targeted as a zero-day. This trend highlights an ongoing focus on Cisco products by threat actors, with their SD-WAN solutions also seeing multiple vulnerabilities exploited this year.

As companies worldwide continue to rely on Unified CM for critical operations, prompt attention to security updates and patches remains essential to prevent potential breaches and maintain robust cybersecurity defenses.

Security Week News Tags:Cisco, CVE-2026-20230, Cybersecurity, Defused, enterprise security, Exploitation, Hackers, remote code execution, security patch, SSD Secure Disclosure, SSRF attacks, state-sponsored threat, Unified CM, Vulnerability, WebDialer service

Post navigation

Previous Post: Anthropic AI Exposes Security Gaps in U.S. Systems
Next Post: Beware of GTA 6 Scam Sites Exploiting Gamers

Related Posts

Trump Advocates for Extending Surveillance Program Amid Privacy Concerns Trump Advocates for Extending Surveillance Program Amid Privacy Concerns Security Week News
Code Execution Vulnerability Patched in GitHub Enterprise Server Code Execution Vulnerability Patched in GitHub Enterprise Server Security Week News
Alleged Conti, TrickBot Gang Leader Unmasked Alleged Conti, TrickBot Gang Leader Unmasked Security Week News
Denmark Blames Russia for Cyberattacks Ahead of Elections and on Water Utility Denmark Blames Russia for Cyberattacks Ahead of Elections and on Water Utility Security Week News
Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Nvidia Triton Vulnerabilities Pose Big Risk to AI Models Security Week News
Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark