Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
What happened
Researchers observed active exploitation of a high-severity SSRF flaw (CVE-2026-20230) in Cisco Unified Communications Manager that can be chained to write files and gain root on devices. Cisco released fixes earlier in the month but defenders report live probes and exploit activity; affected appliances should be assumed exploitable until patched and validated. Watch for new proof-of-concept details and supplier advisories that define affected versions and mitigation steps
Why the category manager should care
Prioritize patch evidence and verified testing from UC suppliers because exploited CUCM instances allow root-level compromise of telephony infrastructure
Key facts
- CVE-2026-20230: SSRF to root file-write
- Cisco published security updates earlier in June
- Exploit activity observed by threat intelligence