Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
ID: 183b5348-e122-533c-9be8-514df357a86b
STIX ID: report--183b5348-e122-533c-9be8-514df357a86b
Feed Name: The Hacker News
Threat Score
Executive summary: A critical SSRF vulnerability (CVE-2026-20230, CVSS 8.6) in Cisco Unified Communications Manager / SME allows unauthenticated attackers to craft HTTP requests that can write files to the server and potentially escalate to root. Active exploitation has been observed from a single source using an unvetted PoC; Cisco has released patches (14SU6 and 15SU5) and recommends disabling the WebDialer service (disabled by default) as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
