CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploited
CISA KEV: Cisco Unified Communications Manager SSRF to (TL-2026-0960), also tracked as cisco-sa-cucm-ssrf-cXPnHcW, is a critical-severity software vulnerability scored CVSS 8.6, first published 2026-06-27 and last reviewed 2026-08-19. It has no confirmed attribution, affects Cisco Unified Communications Manager (Unified CM), references 2 CVEs (CVE-2026-20230, CVE-2026-12569), maps to 28 MITRE ATT&CK techniques (T1005, T1018, T1027), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-0960
- Threat ID
- TL-2026-0960
- Also known as
- cisco-sa-cucm-ssrf-cXPnHcW
- Severity
- CRITICAL
- CVSS
- 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-06-27
- Last reviewed
- 2026-08-19
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, ai-ml, cloud, finance, research, government administration
- Target regions
- Global, North America, Europe, Asia Pacific
- Detection rules
- 9
- Indicators of compromise
- 23
- Updates
- 2026-08-19
Malware and tooling in CISA KEV: Cisco Unified Communications Manager SSRF to
Malware and tooling: JSP Webshell (Windchill hex-named variant), JSP Webshell (two-stage UCM variant), Apache Axis2 web service framework, Tor anonymization network (CVE-2026-20230 C2)
CVE-2026-20230 is an unauthenticated Server-Side Request Forgery in Cisco Unified Communications Manager's WebDialer service, actively exploited to deploy two-stage JSP webshells via Apache Axis2 service abuse. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on June 25, 2026 with a BOD 26-04 federal remediation deadline of June 28, 2026. Attackers route C2 traffic through Tor and are conducting automated mass-exploitation sweeps against internet-exposed UCM instances.
How CISA KEV: Cisco Unified Communications Manager SSRF to works
CVE-2026-20230 is a Server-Side Request Forgery (CWE-918) vulnerability in the WebDialer component of Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Cisco published advisory cisco-sa-cucm-ssrf-cXPnHcW on June 3, 2026. The vulnerability allows an unauthenticated remote attacker to send specially crafted HTTP requests to the WebDialer service, exploiting its failure to properly validate inbound request parameters.
The exploitation chain proceeds in two stages. In the first stage, the attacker leverages the SSRF to force the WebDialer service to make unintended internal HTTP requests, which are used to install a rogue Apache Axis2 web service on the target. The target hostname required to craft the SSRF payload is obtainable via a separate unauthenticated endpoint, removing it as a meaningful barrier to exploitation. In the second stage, the attacker uses the newly installed Axis2 service to write a JSP file-writer payload to disk, which is subsequently used to drop a full command-execution webshell into the /platform-services/axis2-web/ directory of the application server. The resulting webshell provides unauthenticated remote command execution with the privileges of the application server process, effectively achieving full system compromise from an unauthenticated HTTP request.
WebDialer is disabled by default in Cisco Unified CM, but is routinely enabled by organizations using click-to-call functionality — a common deployment pattern in healthcare, financial services, government, and telecommunications environments. Affected releases include Unified CM 14.0 through 14SU5 and 15.0 through 15SU4a, and all equivalent SME versions. Fixed releases are 14SU6 and 15SU5; Cisco also released interim COP patches for the 15.x branch.
A public proof-of-concept exploit was released on June 5, 2026 — two days after the advisory. Active exploitation was first observed by Defused Cyber honeypots on June 22–23, 2026, confirming automated sweeps targeting internet-exposed UCM instances. A second, more complete PoC was published June 25, 2026. All observed attacker C2 traffic has been routed through the Tor anonymization network, making attribution difficult. CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities catalog on June 25, 2026, imposing a BOD 26-04 federal remediation deadline of June 28, 2026.
This KEV entry was published simultaneously with CVE-2026-12569, a critical unauthenticated Java deserialization RCE in PTC Windchill PDMlink and FlexPLM (CVSS 9.8). The PTC vulnerability has confirmed C2 infrastructure (5.180.41.35) and is being exploited to deploy JSP webshells with naming pattern /Windchill/login/[0-9a-f]{16}.jsp, targeting manufacturing, engineering, and PLM-heavy sectors.
For CVE-2026-20230, immediate mitigation options include: (1) applying the vendor patch (14SU6 or 15SU5), (2) disabling the WebDialer service if click-to-call is not required, and (3) restricting internet access to Unified CM management interfaces. The threat actor identity remains unknown; no formal attribution has been made as of June 27, 2026.
MITRE ATT&CK techniques used in TL-2026-0960
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1049 System Network Connections Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1610 Deploy Container
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Persistence
T1505 Server Software Component; T1543 Create or Modify System Process
Impact
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1592 Gather Victim Host Information; T1595 Active Scanning
defense-impairment
Affected products and versions in CISA KEV: Cisco Unified Communications Manager SSRF to
- Cisco — Unified Communications Manager (Unified CM)
Vulnerable versions: 14.0; 14SU1; 14SU2; 14SU3; 14SU4; 14SU5; 15.0; 15SU1; 15SU2; 15SU3
Fixed in: 14SU6; 15SU5 - Cisco — Unified Communications Manager Session Management Edition (SME)
Vulnerable versions: 14.0 through 14SU5 equivalent; 15.0 through 15SU4a equivalent
Fixed in: 14SU6 SME; 15SU5 SME - PTC — Windchill PDMlink
Vulnerable versions: all versions through 13.1.3.0; 11.0 through 11.0 M030 pre-patch; 11.1 through 11.1 M020 pre-patch; 11.2 through 11.2.0 pre-patch; 12.0 through 12.0.1; 12.1 through 12.1.1; 13.0 through 13.0.1; 13.1 through 13.1.0
Fixed in: 13.1.1; 13.0.2; 12.1.2; 12.0.2; 11.2.1; 11.1 M020; 11.0 M030 - PTC — FlexPLM
Vulnerable versions: all versions through 13.0.3.0
Fixed in: See PTC advisory CS473270 for branch-specific fix versions
Remediation for CISA KEV: Cisco Unified Communications Manager SSRF to
Patches
- Cisco Unified CM 14.x: Upgrade to 14SU6
- Cisco Unified CM 15.x: Upgrade to 15SU5 (or apply interim COP patch)
- Cisco Unified CM SME: Apply equivalent 14SU6 or 15SU5 SME release
- PTC Windchill PDMlink 13.1.x: Apply 13.1.1 patch
- PTC Windchill PDMlink 13.0.x: Apply 13.0.2 patch
- PTC Windchill PDMlink 12.1.x: Apply 12.1.2 patch
- PTC Windchill PDMlink 12.0.x: Apply 12.0.2 patch
- PTC Windchill PDMlink 11.2.x: Apply 11.2.1 patch
- PTC Windchill PDMlink 11.1.x: Apply 11.1 M020 patch
- PTC Windchill PDMlink 11.0.x: Apply 11.0 M030 patch
Immediate actions
- Disable WebDialer service immediately if click-to-call functionality is not required (Cisco Unified Serviceability → Control Center – Feature Services → CTI Services)
- Block internet-facing access to Unified CM WebDialer port/endpoints at perimeter firewall
- Hunt for webshells in /platform-services/axis2-web/ on all UCM nodes
- Block Tor exit node traffic at perimeter to disrupt observed C2 channel
- Block CVE-2026-12569 C2 server 5.180.41.35 and attacker IPs 172.111.38.31, 216.152.148.54, 104.243.35.131, 74.50.76.146 at perimeter
Workarounds
- Disable WebDialer service in Cisco Unified Serviceability if not needed
- Restrict network access to UCM WebDialer port from internet-facing segments
Longer-term hardening
- Restrict Unified CM administrative and WebDialer interfaces to management VLANs only
- Deploy WAF or reverse proxy in front of internet-facing UCM with request inspection
- Implement continuous monitoring of the axis2-web directory for new JSP file creation
- Audit all externally accessible Cisco Unified CM and SME deployments for internet exposure
- Establish recurring patching cadence for Cisco collaboration infrastructure
- For PTC Windchill/FlexPLM: hunt for webshells matching /Windchill/login/[0-9a-f]{16}.jsp
CVEs associated with CISA KEV: Cisco Unified Communications Manager SSRF to
Weaknesses (CWE) in CISA KEV: Cisco Unified Communications Manager SSRF to
CWE-918, CWE-502, CWE-20
Timeline of CISA KEV: Cisco Unified Communications Manager SSRF to
- Cisco published security advisory cisco-sa-cucm-ssrf-cXPnHcW for CVE-2026-20230, disclosing the SSRF vulnerability in the WebDialer component of Unified CM and SME. Fixed releases 14SU6 and 15SU5 made available simultaneously.
- First public proof-of-concept exploit code released for CVE-2026-20230, demonstrating the full SSRF-to-webshell attack chain via Apache Axis2 service abuse. Horizon3.ai published technical analysis detailing how an unauthenticated attacker can achieve RCE.
- PTC released emergency patches for CVE-2026-12569 (co-KEV) across all supported Windchill PDMlink and FlexPLM branches after notifying customers of a critical unauthenticated Java deserialization RCE vulnerability.
- Active exploitation of CVE-2026-20230 first confirmed in the wild via Defused Cyber honeypot infrastructure. Automated sweeps observed targeting internet-exposed Unified CM instances, dropping two-stage JSP webshells into the axis2-web directory.
- Multiple security vendors including Help Net Security and SecurityWeek confirmed ongoing webshell deployments against Cisco Unified CM. All observed C2 callback traffic was routed through the Tor anonymization network, masking attacker origin.
- Detailed analysis of webshell behavior published: webshells confirmed dropping to /platform-services/axis2-web/ with command execution capabilities. PTC Windchill exploitation also confirmed with JSP webshells following the /Windchill/login/[0-9a-f]{16}.jsp naming pattern.
- CISA added CVE-2026-20230 (Cisco UCM SSRF) and CVE-2026-12569 (PTC Windchill/FlexPLM deserialization RCE) to the Known Exploited Vulnerabilities catalog simultaneously. BOD 26-04 federal remediation deadline set for June 28, 2026. Second, more complete PoC for CVE-2026-20230 also published the same day.
- BleepingComputer and major security media outlets reported on the CISA KEV additions and the impending federal deadline. Ongoing active exploitation continued to be observed with no attribution identified.
- CISA BOD 26-04 federal remediation deadline. All U.S. Federal Civilian Executive Branch (FCEB) agencies required to have patched or mitigated CVE-2026-20230 and CVE-2026-12569, or discontinued use of affected products, per Binding Operational Directive 26-04.
Update history for TL-2026-0960
- 2026-08-19 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s).
Sources cited for CISA KEV: Cisco Unified Communications Manager SSRF to
- CISA Sets Urgent Deadline to Fix Cisco Flaw Exploited in Attacks
- Cisco Security Advisory: cisco-sa-cucm-ssrf-cXPnHcW
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (June 25, 2026)
- CISA Known Exploited Vulnerabilities Catalog JSON Feed
- NVD CVE Detail: CVE-2026-20230
- Horizon3.ai: CVE-2026-20230 — Cisco Unified CM SSRF to RCE
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
- Cisco Unified CM Flaw Exploited to Drop Webshells (CVE-2026-20230)
- Hackers Exploiting Cisco Unified CM Vulnerability
- CVE-2026-20230 SSRF to RCE Technical Analysis
- Cisco Unified CM SME Flaw CVE-2026-20230 Now Exploited in Attacks
- CISA Adds Exploited PTC Windchill RCE Flaw to KEV (CVE-2026-12569)
- PTC Trust Center Advisory: Windchill PDMlink / FlexPLM RCE
- NVD CVE Detail: CVE-2026-12569
- Hackers Exploit Critical PTC Windchill PLM Software Flaw (CVE-2026-12569)
Threats related to CISA KEV: Cisco Unified Communications Manager SSRF to
- CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root)
- CVE-2026-12569: PTC Windchill PDMLink / FlexPLM Unauthenticated Deserialization RCE (CISA KEV, JSP Web Shell Campaign)
- CVE-2026-20230: Cisco Unified Communications Manager WebDialer SSRF Actively Exploited to Drop Tor-Routed JSP Webshells via Rogue Apache Axis Service, CISA Sets June 28 Deadline
- CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF - Critical Remote Code Execution Vulnerabilities
- CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise
- Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245)
Detection coverage for TL-2026-0960
As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0960 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0960
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.