Cisco Unified CM SSRF Exploited, Patch by June 28
CVE-2026-20230 is a server-side request forgery flaw in Cisco Unified CM and Unified CM SME added to CISA KEV on June 25. Federal deadline is June 28.
If you run Cisco Unified Communications Manager with WebDialer enabled, an unauthenticated attacker can write arbitrary files to the underlying operating system and use them to escalate to root. CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities catalog on June 25, 2026, with a federal remediation deadline of June 28.
Am I affected?
CVE-2026-20230 affects the following releases, per Cisco’s advisory:
- Cisco Unified Communications Manager (Unified CM) Release 14
- Cisco Unified Communications Manager (Unified CM) Release 15
- Cisco Unified Communications Manager Session Management Edition (Unified CM SME) Release 14
- Cisco Unified Communications Manager Session Management Edition (Unified CM SME) Release 15
Prerequisite for exploitation: the WebDialer service must be enabled. It is disabled by default. Organizations that turned it on for click-to-call, CTI integrations, or softphone workflows are exposed. Confirm whether WebDialer is active before concluding you are not at risk.
What to do now
Patch steps from Cisco’s advisory:
- Release 14: upgrade to 14SU6 or later. This update is available now via the Cisco Support and Downloads portal.
- Release 15: upgrade to 15SU5, expected September 2026. If you cannot wait for 15SU5, apply the COP1 patch as an interim fix.
If you cannot patch immediately: disable the WebDialer service through the Cisco Unified CM Administration interface (Serviceability > Service Activation). This removes the attack vector for this flaw but is not a permanent fix; apply the patch as soon as it is practical.
Federal agencies are under CISA’s BOD 26-04 deadline of June 28, 2026. That is two days from today. For all other organizations running Unified CM with WebDialer enabled, the same window is a reasonable internal target.
How it is being exploited
CVE-2026-20230 is a CWE-918 server-side request forgery vulnerability with a CVSS 3.1 base score of 8.6 (HIGH), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N, published by NVD on June 3, 2026. An unauthenticated attacker sends crafted HTTP requests to the WebDialer service; improper input validation lets those requests write files to the underlying operating system. Those files can then be used to escalate privileges to root.
Cisco’s advisory notes that proof-of-concept exploit code is publicly available. CISA’s addition to the KEV catalog on June 25, 2026 reflects confirmed in-the-wild exploitation. EPSS rates this flaw at 34.2 percent (98th percentile) as of June 25, 2026, placing it in the top two percent of all tracked CVEs by exploitation likelihood.
No ransomware campaign use has been confirmed at this writing. For the latest technical detail, work from Cisco’s advisory and the CISA KEV entry directly.
How VulnMonitor helps
Cisco Unified CM is an internal voice-infrastructure component, which means it may not surface in an external perimeter scan. VulnMonitor matches CISA KEV additions against your live asset inventory, so if you are running an affected release of Unified CM or Unified CM SME with WebDialer enabled, this CVE sorts to the top of your remediation queue within minutes of the KEV add. It does not prevent the exploit from running, so the patch and the WebDialer check above are still the actions that close the risk. Knowing which assets are in scope is the first step toward closing it.
Updates
- 2026-06-26 Initial post. CVE-2026-20230 added to CISA KEV on June 25, 2026. Federal deadline June 28, 2026. Release 15 patch (15SU5) not yet available; COP1 patch is the interim fix.