惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Vercel News
Vercel News
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
量子位
Engineering at Meta
Engineering at Meta
B
Blog RSS Feed
博客园 - 【当耐特】
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
IT之家
IT之家
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Jina AI
Jina AI
博客园 - 三生石上(FineUI控件)

CSO Online

New malware turns Linux systems into P2P attack networks Poisoned truth: The quiet security threat inside enterprise AI Train like you fight: Why cyber operations teams need no-notice drills Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS
Attackers exploit Cisco Unified CM flaw weeks after patch...
Gyana Swain · 2026-06-24 · via CSO Online

New activity targets CVE‑2026‑20230, an SSRF bug that can allow unauthenticated file writes and potential root‑level access on vulnerable systems.

A critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow attackers to gain root access.

Threat intelligence firm Defused reported the exploitation on June 23. The company said it observed the activity over the weekend.

“This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys,” Defused said on X.

The flaw is tracked as CVE-2026-20230 and carries a CVSS base score of 8.6. Cisco published the advisory and patches on June 3, when it stated it was not aware of any malicious use of the vulnerability at the time of disclosure.

“This vulnerability is due to improper input validation for specific HTTP requests,” Cisco said in the advisory.  “An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device.”

The flaw could allow an unauthenticated, remote attacker to “conduct server-side request forgery (SSRF) attacks through an affected device,” the advisory said. A successful exploit could let the attacker write files to the underlying operating system and elevate privileges to root, it added.

No prior record of exploitation

Defused said the weekend activity was the first exploitation of the flaw it had recorded. “No previously recorded exploitation, and not yet listed in CISA KEV,” it wrote in the X post.

Weeks before Defused reported the attacks, Cisco had acknowledged in its advisory that proof-of-concept exploit code for the flaw was already available. The Cisco Product Security Incident Response Team (PSIRT) was not aware of any malicious use of the vulnerability when the advisory was published, the company said.

Cisco did not immediately respond to a request for comment.

WebDialer service must be enabled

The flaw affects Cisco Unified CM and Unified CM SME products widely used by enterprises to manage voice, video, messaging, mobility, and conferencing services across corporate environments.

The company said the flaw can be exploited remotely if the targeted system is running a vulnerable software release and has the WebDialer service enabled.

“WebDialer is disabled by default,” Cisco noted in the advisory.

Cisco said it found no workaround that would completely address the vulnerability.

“There are no workarounds that address this vulnerability,” the company said in its advisory. “However, as a mitigation, administrators may disable the WebDialer service until a patch can be applied.”

Researcher details the file-write chain

The flaw was reported to Cisco by an independent security researcher working with SSD Secure Disclosure, Cisco said.

While Cisco’s advisory describes the issue as an SSRF vulnerability, SSD’s analysis indicates that multiple weaknesses can be combined to achieve a broader compromise of an affected system.

“The CUCM product faces a few vulnerabilities that when bundled together allow a remote attacker to gain the ability to write arbitrary files on the server, which in turn allow an unauthenticated attacker to execute code,” SSD Secure wrote in a technical write-up.

SSD said the attack chain begins with an SSRF vulnerability and can be leveraged to write arbitrary files to the server. According to the disclosure, those file-write capabilities can then be used to execute code on the affected system.

Patching and mitigation

Cisco said there are no workarounds that address the vulnerability and advised customers to upgrade to fixed software releases.

The company said the fix for the Cisco Unified CM and Unified CM SME 14 release train is 14SU6, and for the 15 train, the fix is in 15SU5, due in September 2026, or in an interim COP patch.

Neither Cisco nor Defused has publicly attributed the attacks to a specific threat actor, released indicators of compromise, or disclosed whether any organizations have been successfully compromised through exploitation of the flaw.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.