Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop
A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

Cisco patched it on June 3. By June 23, someone was already swinging at it.
Threat intelligence firm Defused reported active exploitation of CVE-2026-20230 over the weekend, describing inbound traffic from a single source using "genuinely-formatted file:// file-write payloads" hitting their decoys. CVSS base score is 8.6. Not theoretical anymore.
The flaw lives in Cisco Unified Communications Manager and Unified CM SME — the platforms enterprises use to glue together voice, video, and conferencing infrastructure. In practice, the attack surface is gated by one configuration detail: the WebDialer service has to be enabled. Cisco notes it's off by default, which is the saving grace here. But "disabled by default" and "disabled in your environment" are two very different things, and any admin who turned it on for click-to-dial convenience is now the person with a problem.
The failure mode here is a chained exploit, not a single clean vulnerability. Cisco's advisory frames this as an SSRF issue — an unauthenticated remote attacker sends a crafted HTTP request and rides the server-side forgery to write files to the underlying OS, then escalates to root. SSD Secure Disclosure, whose researcher originally found and reported the flaw, goes further. Their technical writeup describes multiple weaknesses bundled together, moving from SSRF through arbitrary file write to unauthenticated remote code execution on the affected host.
Root. No credentials required. That's the ceiling.
Cisco acknowledged that proof-of-concept code was already circulating before the advisory went out — which is a rough position to be in. You're racing against PoC availability the moment you publish, and three weeks is apparently enough runway for someone to start probing production systems. CISA has not yet added this to the Known Exploited Vulnerabilities catalog as of Defused's disclosure, though that status can change quickly once active exploitation is confirmed.
There is no workaround that fully addresses the vulnerability. Cisco's guidance is to patch or, as a stopgap, disable WebDialer until you can. For the 14.x train, target release 14SU6. For 15.x, the full fix lands in 15SU5 in September 2026, with an interim COP patch available now.
Neither Cisco nor Defused has attributed the activity to a known threat actor or confirmed whether any organization was successfully compromised.
One thing the post-mortem will say: someone had WebDialer running and hadn't applied a three-week-old patch.
Operational takeaway: Pull your Unified CM WebDialer service status right now — utils service list from the CLI — and if you haven't applied the June 3 patches, that's your weekend.



