惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
D
DataBreaches.Net
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
小众软件
小众软件
美团技术团队
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
D
Docker
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
H
Hackread – Cybersecurity News, Data Breaches, AI and More
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
S
SegmentFault 最新的问题
云风的 BLOG
云风的 BLOG
B
Blog
雷峰网
雷峰网
The Cloudflare Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Critical Cisco Unified CM and SME Flaw Enables Remote Att...
Abinaya · 2026-06-24 · via Cyber Security News

Cisco has warned customers about a critical server-side request forgery (SSRF) flaw in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME) that allows remote, unauthenticated attackers to write files on the underlying OS and potentially gain root privileges.

Tracked as CVE-2026-20230 and rated Critical by Cisco despite a CVSS v3.1 base score of 8.6, the issue stems from improper input validation in the WebDialer component.

The vulnerability exists because specific HTTP requests processed by Unified CM and Unified CM SME are not sufficiently validated when the Cisco WebDialer Web Service is enabled.

An attacker can exploit this weakness by sending crafted HTTP requests to the WebDialer endpoint, abusing the application’s trust in internal resources to trigger SSRF.

Cisco Unified CM and SME Flaw

Once the SSRF condition is established, the attacker can force the system to create arbitrary files on the underlying operating system.

These files can then be leveraged to escalate privileges to root, giving the adversary complete control over the Unified CM server, including configuration, call control, and underlying services.

Although CVE-2026-20230 has a CVSS v3.1 base score of 8.6, Cisco has assigned the flaw a Security Impact Rating of Critical because realistic exploitation can lead to root-level compromise.

The network-based, unauthenticated, low-complexity nature of the attack significantly lowers the barrier to exploitation for remote attackers.

A successful attack could enable adversaries to tamper with call routing, inject or modify configuration files, implant backdoors, and pivot deeper into voice and collaboration networks.

In large Unified CM deployments, the compromise of a core call-control node can result in widespread service disruption and a strategic foothold for lateral movement.

The vulnerability affects Cisco Unified CM and Unified CM SME installations where the Cisco WebDialer Web Service is enabled in the CTI Services section.

WebDialer is disabled by default, so only systems where administrators have intentionally enabled this feature are exposed to CVE-2026-20230.

Cisco’s advisory links the flaw to bug ID CSCws67331 and identifies fixed releases for major trains: Unified CM and Unified CM SME 14 are remediated in 14SU6, while 15-series customers must upgrade to 15SU5 (or deploy an available COP patch).

The Cisco PSIRT has confirmed the availability of proof-of-concept exploit code but, at the time of initial disclosure, had no evidence of active malicious exploitation in the wild.

A typical exploitation chain begins when a remote attacker sends a specially crafted HTTP request to the WebDialer interface on an affected Unified CM or Unified CM SME instance.

Due to improper input validation, the application processes attacker-controlled URLs, causing the server to issue internal HTTP requests that result in arbitrary file creation on the host system.

With file-write capabilities in place, the attacker can plant malicious scripts or modify system and application configuration files to execute code with elevated privileges and eventually attain root access.

Mitigation Steps

Once root is obtained, the Unified CM platform can be weaponized for persistence, signaling traffic surveillance, or further compromise of adjacent systems in the UC environment.

Cisco states that there are no true workarounds and that upgrading to a fixed software release is the only complete remediation for CVE-2026-20230.

As a temporary mitigation, administrators can disable the Cisco WebDialer Web Service via the Cisco Unified Serviceability interface, provided it is not required for business operations.

Organizations should prioritize upgrading to Unified CM 14SU6 or later, or to Unified CM SME 15SU5 (or the relevant COP1 patch), aligning their deployments with the guidance in Cisco’s advisory and bug CSCws67331.

Until patches are fully deployed, defenders should restrict management interfaces to trusted networks and monitor for unusual HTTP activity and unexpected file creation on Unified CM servers.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.