logo

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

ID: 2a2a8f71-f8c9-5823-a73a-14374ed63d4e

STIX ID: report--2a2a8f71-f8c9-5823-a73a-14374ed63d4e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Lawrence Abrams

...
...

A high-severity SSRF vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager allows unauthenticated attackers to perform server-side request forgery that can write files to the underlying OS and lead to root privilege escalation; proof-of-concept details were published by SSD Secure and active reconnaissance exploitation was observed by Defused targeting vulnerable devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.