Cisco UCM SSRF Bug Allows Unauthenticated RCE as Root, Under Exploitation (opens in new tab)
On June 3, Cisco disclosed CVE-2026-20230, a Server-Side Request Forgery (SSRF) vulnerability in the WebDialer service of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). An unauthenticated remote attacker can exploit the flaw by sending a crafted HTTP request to an affected device, allowing them to write files to the underlying operating system that can subsequently be leveraged to escalate privileges to r...
Read the original article