Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    [Control systems] CISA ICS security advisories (AV26–530)

    June 4, 2026

    SSA-566905 V1.3 (Last Update: 2024-09-10): Multiple Denial of Service Vulnerabilities in the Webserver of Industrial Products

    June 4, 2026

    Cisco warns of critical Unified CM flaw with PoC exploit code

    June 4, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Cisco warns of critical Unified CM flaw with PoC exploit code
    News

    Cisco warns of critical Unified CM flaw with PoC exploit code

    adminBy adminJune 4, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cisco

    Cisco has released security updates to patch a critical-severity Unified Communications Manager (Unified CM) flaw that allows attackers to gain root privileges.

    Cisco Unified CM (formerly known as Cisco CallManager) serves as the central control system for Cisco IP telephony systems, handling device management, call routing, and telephony features.

    The vulnerability (tracked as CVE-2026-20230) can be exploited remotely by threat actors without privileges in low-complexity server-side request forgery (SSRF) attacks.

    image

    “An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root,” Cisco said.

    “Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.”

    Cisco’s Product Security Incident Response Team (PSIRT) is aware of publicly available proof-of-concept exploit code for CVE-2026-20230, but has yet to find evidence of active exploitation or targeting.

    Luckily, the vulnerability only impacts systems where the WebDialer service is enabled, and WebDialer is disabled by default.

    To check whether WebDialer is enabled, log in to Cisco Unified CM Administration, go to “Cisco Unified Serviceability,” click “Go,” and check the service status in the Tools > CTI Services menu under “Control Center – Feature Services.”

    While there are no workarounds to mitigate this vulnerability, and it’s highly recommended to install Cisco Unified CM versions 14SU6 or 15SU5 (Sep 2026 or COP), administrators can also disable the WebDialer service until a patch is applied to block any incoming CVE-2026-20230 attacks.

    To disable WebDialer, go through the following steps:

    1. Log in to the Cisco Unified CM Administration interface.
    2. From the ‘Navigation’ menu, choose ‘Cisco Unified Serviceability and click Go.
    3. From the ‘Tools’ menu, choose ‘Service Activation.’
    4. In the ‘CTI Services’ section of the page, uncheck the ‘Cisco WebDialer Web Service’ checkbox, then click Save.

    In January, Cisco fixed another critical Unified CM vulnerability (CVE-2026-20045) that has been actively exploited as a zero-day in remote code execution attacks.

    Over the past several years, the company also removed a Unified CM backdoor account that allowed remote attackers to log in to unpatched devices with root privileges, and patched another flaw (CVE-2024-20253) that enabled threat actors to gain root access to vulnerable systems.

    Over the past five years, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) tagged 91 Cisco vulnerabilities as actively exploited in the wild, six of which have been used by various ransomware operations.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDebian Ceph Critical DoS Priv Escalation Disclosures DSA-6321-1
    Next Article SSA-566905 V1.3 (Last Update: 2024-09-10): Multiple Denial of Service Vulnerabilities in the Webserver of Industrial Products
    admin
    • Website

    Related Posts

    News

    Google adds Android protection against AI deepfake scam calls

    June 4, 2026
    News

    Companies Are Using Reddit to Manipulate ChatGPT and Google AI Search

    June 4, 2026
    News

    CISA warns of cyberattacks targeting fuel tank monitoring systems

    June 3, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    [Control systems] CISA ICS security advisories (AV26–530)

    June 4, 2026

    SSA-566905 V1.3 (Last Update: 2024-09-10): Multiple Denial of Service Vulnerabilities in the Webserver of Industrial Products

    June 4, 2026

    Cisco warns of critical Unified CM flaw with PoC exploit code

    June 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.