Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Critical Cisco vulnerability actively exploited in attacks against CUCM servers

Cisco CUCM vulnerability is actively exploited in attacks against servers Cisco CUCM vulnerability is actively exploited in attacks against servers
Illustration of the critical Cisco vulnerability CVE-2026-20230 that is now being exploited in attacks against CUCM servers.

A serious security flaw in Cisco Unified Communications Manager (CUCM) is now being actively exploited in attacks. The vulnerability, identified as CVE-2026-20230, could allow attackers to gain root privileges on affected systems and take full control of the device.

Cisco released security updates for the vulnerability June 3 and at the same time warned that the flaw could be used to elevate privileges and compromise underlying systems.

Vulnerability affects both Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). According to Cisco it is about a SSRF vulnerability, so-called Server-Side Request Forgery, which is due to a lack of validation of certain HTTP requests.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

An attacker could send specially crafted HTTP requests to a vulnerable device, thereby writing files to the operating system. These files could then be used to elevate privileges and ultimately give the attacker root access.

Active exploitation has now been detected

Threat intelligence firm Defused reported over the weekend that the vulnerability is now being actively exploited in attacks.

According to Defused, the attacks come from the same IP address and use specially designed file://-baserade payloads to create files on the vulnerable systems.

The attacks observed so far appear to be primarily reconnaissance in nature. Among other things, the attackers are attempting to create the file:

Cisco CVE-2026-20230 exploit on honeypots

The aim appears to be to identify which systems are still vulnerable rather than immediately compromising them.

The WebDialer component takes center stage

The security company SSD Secure, which discovered the vulnerability, has since published technical details about the error.

The researchers found that an unauthenticated attacker can abuse the WebDialer component's handling of user-controlled URLs. By using file://-URI the attacker can force the application to write files directly to the operating system.

By controlling both file paths and content, an attacker can ultimately achieve remote code execution and subsequently obtain root privileges on the affected device.

SSD Secure noted that the attacker first needs to know the hostname of the target system before the attack can be carried out. However, the researchers showed that in some cases this information can be retrieved from the system before the actual exploitation begins.

Cisco – Critical Cisco vulnerability actively exploited in attacks against CUCM servers | IT Industry

The risk increases after publication

Although the current attacks seem to be primarily aimed at mapping vulnerable systems, the threat landscape is expected to change rapidly.

Now that technical details and concept code have been made public, the risk increases that more threat actors will start targeting unprotected CUCM servers. Organizations that use Cisco Unified Communications Manager It is therefore recommended to immediately install the security updates that Cisco has provided.

Security experts also urge organizations to monitor their systems for

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT