Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately
A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

Key points
- Cisco confirmed on Wednesday that attackers are actively exploiting CVE-2026-20230, a flaw in its Unified Communications Manager software used by businesses to run phone and video systems.
- The flaw carries a severity score of 8.6 out of 10 and can give an attacker full administrative, "root", control over the targeted machine.
- Only systems with the WebDialer service switched on are vulnerable; that service is off by default.
- Cisco released a fix in early June 2026 in software version 14SU6, with a second update due in version 15SU5 in September 2026.
- Security research firm SSD Secure Disclosure published a working proof-of-concept before Cisco confirmed the exploitation.
Cisco's Unified Communications Manager, often called Unified CM, is the software businesses use to manage office phone calls and video meetings. Last week, Cisco told SecurityWeek it had seen no malicious use of a known flaw in that software. On Wednesday, it changed its answer.
The vulnerability, tracked as CVE-2026-20230, works through server-side request forgery, where an attacker tricks the server into making web requests on their behalf. That lets the attacker drop unauthorised files onto the machine and climb to root access, meaning they own the entire system. We first reported this flaw on 4 June 2026, when Cisco's PSIRT had not yet observed in-the-wild use.
The failure mode is a familiar one: a PoC, essentially a published recipe for the attack, landed publicly before customer patching had time to catch up.
How did the attackers get in?
Defused spotted the first real-world attacks coming from a single source, using that published PoC. SSD Secure Disclosure, the research group credited with finding the flaw, had posted full technical details and working attack code shortly before. Once that information is public, criminals with modest technical skill can use it.
To pull this off, the targeted system must have had the WebDialer service switched on. WebDialer is a feature that lets browser-based applications dial phone calls. Cisco ships the product with it disabled. Any organisation that turned it on without a business need handed attackers an open door.
An attacker with root access to a phone system can intercept calls or use the compromised server as a foothold into other internal systems. In a hospital or a financial firm, that's not a theoretical problem.
The post-mortem will say: we knew about this in June and hadn't patched.
Cisco is urging customers to upgrade to version 14SU6 now and not wait for 15SU5. If WebDialer isn't specifically needed, disable it. That closes the exposure entirely regardless of patch status.
In practice, the gap between "patch released" and "patch applied" is where nearly every exploited vulnerability lives.
Should you worry?
If your organisation runs Unified CM with WebDialer enabled, yes. If WebDialer is off, you're not currently exposed, though patching is still overdue.
Operational takeaway: Check whether WebDialer is enabled on your Unified CM deployment today. If it isn't needed, turn it off before you even think about the patch schedule.



