A serious security flaw in Cisco Unified Communications Manager (CUCM) is now being actively exploited in attacks. The vulnerability, identified as CVE-2026-20230, could allow attackers to gain root privileges on affected systems and take full control of the device.
Cisco released security updates for the vulnerability June 3 and at the same time warned that the flaw could be used to elevate privileges and compromise underlying systems.
Vulnerability affects both Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). According to Cisco it is about a SSRF vulnerability, so-called Server-Side Request Forgery, which is due to a lack of validation of certain HTTP requests.
An attacker could send specially crafted HTTP requests to a vulnerable device, thereby writing files to the operating system. These files could then be used to elevate privileges and ultimately give the attacker root access.
Active exploitation has now been detected
Threat intelligence firm Defused reported over the weekend that the vulnerability is now being actively exploited in attacks.
According to Defused, the attacks come from the same IP address and use specially designed file://-baserade payloads to create files on the vulnerable systems.
The attacks observed so far appear to be primarily reconnaissance in nature. Among other things, the attackers are attempting to create the file:

The aim appears to be to identify which systems are still vulnerable rather than immediately compromising them.
The WebDialer component takes center stage
The security company SSD Secure, which discovered the vulnerability, has since published technical details about the error.
The researchers found that an unauthenticated attacker can abuse the WebDialer component's handling of user-controlled URLs. By using file://-URI the attacker can force the application to write files directly to the operating system.
By controlling both file paths and content, an attacker can ultimately achieve remote code execution and subsequently obtain root privileges on the affected device.
SSD Secure noted that the attacker first needs to know the hostname of the target system before the attack can be carried out. However, the researchers showed that in some cases this information can be retrieved from the system before the actual exploitation begins.

The risk increases after publication
Although the current attacks seem to be primarily aimed at mapping vulnerable systems, the threat landscape is expected to change rapidly.
Now that technical details and concept code have been made public, the risk increases that more threat actors will start targeting unprotected CUCM servers. Organizations that use Cisco Unified Communications Manager It is therefore recommended to immediately install the security updates that Cisco has provided.
Security experts also urge organizations to monitor their systems for








