logo

Cisco warns of critical Unified CM flaw with PoC exploit code

ID: 0a4cdfe5-a296-51b8-a050-eb41bae1e1ad

STIX ID: report--0a4cdfe5-a296-51b8-a050-eb41bae1e1ad

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Sergiu Gatlan

...
...

Cisco released security updates for CVE-2026-20230, a critical SSRF vulnerability in Unified Communications Manager that can be exploited remotely to write files and potentially achieve root privileges; proof-of-concept code exists but Cisco reports no evidence of active exploitation, and recommended mitigations are installing the provided patches (14SU6/15SU5) or disabling the WebDialer service until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.