CVE-2026-20230: Cisco Unified CM SSRF-to-Root Flaw Confirmed Exploited In-the-Wild — 200+ Internet-Exposed Instances Tracked by Shadowserver
Cisco confirmed on July 2, 2026 that CVE-2026-20230 (CVSS 8.6, rated Critical by Cisco due to root escalation potential) in Unified Communications Manager and Unified CM SME is being actively exploited after threat detection firm Defused observed attackers using file:// payloads to write arbitrary files to targeted devices. The unauthenticated SSRF flaw triggers via crafted HTTP requests to the WebDialer service and can be chained to gain root; public PoC has been available since June 5, with Shadowserver currently tracking over 200 internet-exposed instances predominantly across Asia and North America. Organizations should upgrade to Unified CM 14SU6 immediately or disable WebDialer as an interim mitigation — particularly those in healthcare, government, and financial services where Unified CM is mission-critical.
Organizations should upgrade to Unified CM 14SU6 immediately or disable WebDialer as an interim mitigation — particularly those in healthcare, government, and financial services where Unified CM is mission-critical.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.