logo

Critical Cisco CUCM Flaw Exploited Within 24 Hours of PoC Release

ID: c945aaba-7d58-5d72-94d9-281469c05e88

STIX ID: report--c945aaba-7d58-5d72-94d9-281469c05e88

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-26

...
...

**Executive Summary:** A critical SSRF vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager's WebDialer was actively exploited within 24 hours of a public proof-of-concept, enabling unauthenticated attackers to write files to the OS and escalate to root; Cisco released patches on June 3 and advises disabling the WebDialer service until systems are patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.