DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20230PUBLISHED: 2026-06-03
■ HIGHCVE-2026-20230★ CISA KEV LISTED

Cisco Unified CM WebDialer SSRF to Root File Write

VENDOR: Cisco//PRODUCT: Unified Communications Manager (Unified CM) and Unified CM SME
8.6
HIGH
CVSS 3.1
✓
PATCH STATUS
PATCH AVAILABLE
⚡
EXPLOIT STATUS
PUBLIC EXPLOIT

An unauthenticated server-side request forgery (SSRF) flaw (CWE-918) in Cisco Unified CM's WebDialer component allows a remote attacker to send crafted HTTP requests that write arbitrary files to the underlying OS, which can then be leveraged to escalate privileges to root. SSD Secure Disclosure published a full PoC on June 23, 2026; within hours Defused Threat Intelligence confirmed active exploitation via honeypot telemetry observing file-write payloads. Cisco PSIRT confirmed active exploitation in June 2026 and updated the advisory; CISA added to KEV on June 25 (federal deadline June 28). WebDialer is disabled by default — only deployments with it enabled are exposed.

↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
NONE
⊕
Scope / Impact
CHANGED
C:N · I:H · A:N
AFFECTED VERSIONSCisco Unified CM and Unified CM SME versions prior to 14SU6 and 15SU5 with WebDialer service enabled
  • → https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html
  • → https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html
  • → https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20230/
  • → https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn