Cisco’s confirmation that attackers are actively exploiting CVE-2026-20230 makes patching affected Unified Communications Manager systems an immediate priority.
The vulnerability affects Cisco Unified CM and Unified CM Session Management Edition when the WebDialer service is enabled. An unauthenticated remote attacker can send specially crafted HTTP requests and abuse the server-side request forgery flaw to create files on the affected system.
Unified CM is a critical enterprise communication platform responsible for call routing, device management, and telephony services. A successful compromise could disrupt communications, expose system information, establish persistence, or provide attackers with a route into connected internal networks.
Organizations should upgrade to a fixed Cisco release immediately. Systems that cannot yet be patched should disable the WebDialer service until the update can be installed.
Because exploitation is already occurring, patching should be followed by an investigation. Administrators should review web and system logs for unusual requests, unexpected files, configuration changes, suspicious processes, new accounts, and abnormal outbound connections.
Management and application interfaces should also be restricted to trusted networks rather than exposed directly to the internet.
The key lesson is that once exploitation has been confirmed, updating the software is only the first step. Organizations must also determine whether attackers entered before the vulnerability was closed, because patches are excellent at fixing code and remarkably poor at removing intruders already inside.
Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. [...]
Source: Cisco finally confirms attackers exploiting Unified CM flaw via Bleeping Computer — published 02 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.