ADVISORY SUMMARY
A critical-rated (CVSS 8.6, vendor-escalated to Critical SIR) server-side request forgery vulnerability in Cisco Unified CM and Unified CM SME allows unauthenticated remote attackers to write arbitrary files to the underlying OS and escalate to root via the WebDialer component. Public PoC exploit code emerged within 24 hours of June 3 disclosure, active exploitation was confirmed by June 22–23 with attackers deploying multi-stage JSP web shells, and CISA added it to KEV on June 25 with a 3-day remediation deadline for federal agencies. The attack chain is fully automated, uses Tor for obfuscation, and targets enterprise telephony infrastructure across healthcare, government, and financial sectors.
AFFECTED SYSTEMS
MITIGATION GUIDANCE
Upgrade Unified CM to release 14SU6 (version 14) or 15SU5 (version 15) per Cisco advisory cisco-sa-cucm-ssrf-cXPnHcW. If WebDialer is not operationally required, disable it immediately in Cisco Unified Serviceability > Control Center – Feature Services > CTI Services section. Restrict management interface (port 8443) access to trusted networks. Audit /platform-services/axis2-web/ for unauthorized .jsp web shell files.
DETECTION SIGNATURES
Monitor HTTP requests to /cmplatform/installClusterStatusExecute with path traversal sequences (../) in hostname parameters. Alert on anomalous requests to /webdialer/Version.jws?wsdl (reconnaissance phase). Detect new or unexpected .jsw/.wsdd files in Axis2 web directories. Log and alert on pwd=123 parameter in web requests (Stage-2 web shell indicator). Block known Tor exit node IPs at perimeter. Hunt for unexpected file writes to /tmp/ and /platform-services/axis2-web/ directories.
INDICATORS OF COMPROMISE
REFERENCES
- → https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
- → https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
- → https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- → https://nvd.nist.gov/vuln/detail/CVE-2026-20230
- → https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20230/