Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop
A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

Key points
- Threat intelligence firm Defused confirmed active exploitation of CVE-2026-20230 on June 23, three weeks after Cisco patched it on June 3.
- An unauthenticated attacker can chain SSRF through arbitrary file write to reach root on affected hosts.
- The attack only lands if WebDialer is enabled; Cisco ships it off by default, but that default means nothing if an admin toggled it on for click-to-dial.
- Cisco confirmed PoC code was already public at patch time, so defenders had zero head start.
- No workaround fully closes the hole; patch or disable WebDialer until you can.
Cisco patched it on June 3. By June 23, someone was already swinging at it.
Defused reported the activity over the weekend, describing traffic from a single source using "genuinely-formatted file:// file-write payloads" hitting their decoys. CVSS base score is 8.6. Not theoretical anymore.
The flaw lives in Cisco Unified Communications Manager and Unified CM SME, the platforms enterprises use to run voice, video, and messaging infrastructure. One configuration detail gates the attack surface: the WebDialer service must be enabled. Cisco notes it's off by default, which helps. But "disabled by default" and "disabled in your environment" are two different things, and any admin who turned it on for click-to-dial is now the person with a problem.
This is a chained exploit, not a clean single vulnerability. Cisco's advisory frames it as an SSRF issue, an unauthenticated remote attacker sends a crafted HTTP request, rides the server-side forgery to write files to the underlying OS, then escalates to root. SSD Secure Disclosure, whose researcher originally found the flaw, goes further in their technical writeup: multiple weaknesses bundled together move the attacker from SSRF through arbitrary file write to unauthenticated remote code execution.
Root. No credentials required.
We first covered this CVE on 4 June, when the PoC had just dropped and Cisco's PSIRT hadn't yet seen wild attempts. The gap between that story and now is exactly what a three-week-old unpatched exposure looks like.
Cisco confirmed PoC code was circulating before the advisory went out. You're racing against public exploit code the moment you publish, and three weeks was enough runway for someone to start probing production systems. CISA had not added this to the Known Exploited Vulnerabilities catalog as of Defused's June 23 disclosure, though that can change fast once exploitation is confirmed.
There is no workaround that fully closes the flaw. Cisco's guidance: patch, or disable WebDialer as a stopgap. For the 14.x train, target release 14SU6. The 15.x fix ships in 15SU5 in September 2026, with an interim COP patch available now.
Neither Cisco nor Defused has attributed the activity to a known threat actor or confirmed whether any organisation was successfully compromised.
The post-mortem will say someone had WebDialer running and hadn't applied a three-week-old patch.
Operational takeaway: Pull your Unified CM WebDialer service status now, utils service list from the CLI, and if you haven't applied the June 3 patches, that's your weekend.



