DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:01:53ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
UAC-0145 (Sandworm) CRITICAL — UAC-0145 is a confirmed sub-cluster of Sandworm, Russia's GRU-affiliated advanced hacking… /// CYLINDRICALCANINE CRITICAL — CylindricalCanine is a newly named operational subgroup within the China-linked… /// @CrowdStrike CRITICAL — July 2026 Patch Tuesday analysis: CVE-2026-56155 (AD FS EoP, CVSS 7.8) confirmed… /// @MsftSecIntel CRITICAL — Microsoft has confirmed active exploitation of CVE-2026-56155 in Active Directory… /// @GossiTheDog CRITICAL — CVE-2026-56155 ADFS zero-day is nastier than the CVSS 7.8 suggests. Admin on your ADFS…
26Critical Threats
18Active CVEs
10IOCs Tracked
5New Advisories
HIGH#cve

CVE-2026-20230: Cisco Unified CM SSRF-to-Root Flaw Confirmed Exploited In-the-Wild — 200+ Internet-Exposed Instances Tracked by Shadowserver

Cisco confirmed on July 2, 2026 that CVE-2026-20230 (CVSS 8.6, rated Critical by Cisco due to root escalation potential) in Unified Communications Manager and Unified CM SME is being actively exploited after threat detection firm Defused observed attackers using file:// payloads to write arbitrary files to targeted devices. The unauthenticated SSRF flaw triggers via crafted HTTP requests to the WebDialer service and can be chained to gain root; public PoC has been available since June 5, with Shadowserver currently tracking over 200 internet-exposed instances predominantly across Asia and North America. Organizations should upgrade to Unified CM 14SU6 immediately or disable WebDialer as an interim mitigation — particularly those in healthcare, government, and financial services where Unified CM is mission-critical.

Organizations should upgrade to Unified CM 14SU6 immediately or disable WebDialer as an interim mitigation — particularly those in healthcare, government, and financial services where Unified CM is mission-critical.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn