Cisco released security updates on June 3 for a vulnerability, identified as CVE-2026-20230, affecting Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). The updates were released after the exploit intelligence firm Defused reported active attacks exploiting the vulnerability.

Defused reported observing exploitation of CVE-2026-20230 over the weekend. A spokesperson for Defused stated, "This is currently being exploited from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys." Defused also noted that the attacks originate from a single IP address, and the proof-of-concept observed attempts to write a text file named '/tmp/cve-2026-20230-test.txt' to vulnerable devices. Defused stated the CVSS score for the vulnerability is 8.6.

Cisco stated an unauthenticated, remote attacker can exploit CVE-2026-20230 to conduct server-side request forgery (SSRF) attacks. A successful exploit could allow an attacker to write arbitrary files to the underlying operating system and escalate privileges to root. Exploitation of the vulnerability requires the WebDialer service to be enabled, which is disabled by default on Cisco Unified CM. Cisco credited SSD Secure Disclosure with reporting CVE-2026-20230. SSD Secure Disclosure explained that an unauthenticated attacker can abuse the WebDialer component's handling of user-supplied URLs to force the application to write arbitrary files to the operating system using file:// URIs. The firm also stated that an attacker must obtain the target system's hostname before executing the file-write attack.

Cisco initially stated it was not aware of any in-the-wild exploitation of CVE-2026-20230 when it announced patches. CVE-2026-20230 is not currently listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Earlier in 2026, CVE-2026-20045 was the first Cisco Unified CM vulnerability exploited, which involved threat actors targeting it as a zero-day vulnerability. Eight vulnerabilities in Cisco’s SD-WAN products have also been exploited in 2026. Unified CM is Cisco’s on-premises call control and session management platform.