DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:01:53ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
UAC-0145 (Sandworm) CRITICAL — UAC-0145 is a confirmed sub-cluster of Sandworm, Russia's GRU-affiliated advanced hacking… /// CYLINDRICALCANINE CRITICAL — CylindricalCanine is a newly named operational subgroup within the China-linked… /// @CrowdStrike CRITICAL — July 2026 Patch Tuesday analysis: CVE-2026-56155 (AD FS EoP, CVSS 7.8) confirmed… /// @MsftSecIntel CRITICAL — Microsoft has confirmed active exploitation of CVE-2026-56155 in Active Directory… /// @GossiTheDog CRITICAL — CVE-2026-56155 ADFS zero-day is nastier than the CVSS 7.8 suggests. Admin on your ADFS…
26Critical Threats
18Active CVEs
10IOCs Tracked
5New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-20230PUBLISHED: 2026-06-03
HIGHCVE-2026-20230★ CISA KEV LISTED

Cisco Unified CM WebDialer SSRF to Root File Write

VENDOR: Cisco//PRODUCT: Unified Communications Manager (Unified CM) and Unified CM SME
8.6
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

An unauthenticated server-side request forgery (SSRF) flaw (CWE-918) in Cisco Unified CM's WebDialer component allows a remote attacker to send crafted HTTP requests that write arbitrary files to the underlying OS, which can then be leveraged to escalate privileges to root. SSD Secure Disclosure published a full PoC on June 23, 2026; within hours Defused Threat Intelligence confirmed active exploitation via honeypot telemetry observing file-write payloads. Cisco PSIRT confirmed active exploitation in June 2026 and updated the advisory; CISA added to KEV on June 25 (federal deadline June 28). WebDialer is disabled by default — only deployments with it enabled are exposed.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
CHANGED
C:N · I:H · A:N
AFFECTED VERSIONSCisco Unified CM and Unified CM SME versions prior to 14SU6 and 15SU5 with WebDialer service enabled
  • https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html
  • https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html
  • https://horizon3.ai/attack-research/vulnerabilities/cve-2026-20230/
  • https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn