Threat reportVulnerabilityTL-2026-1025

Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245)

criticalACTIVE

Active Exploitation of Cisco Unified Communications Manager (TL-2026-1025), also tracked as Cisco UCM WebDialer SSRF, is a critical-severity software vulnerability scored CVSS 8.6, first published 2026-07-01. It has no confirmed attribution, affects Cisco Unified Communications Manager (Unified CM), references 4 CVEs (CVE-2026-20230, CVE-2026-20245, CVE-2026-20127), maps to 20 MITRE ATT&CK techniques (T1005, T1016, T1041), and is covered by 9 detection rules and 23 indicators of compromise.

CVSS
8.6/10Critical
CVEs
4Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1025

Threat ID
TL-2026-1025
Also known as
Cisco UCM WebDialer SSRF, Cisco Catalyst SD-WAN troot Backdoor, evil_tenant.csv Exploit
Severity
CRITICAL
CVSS
8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
telecoms, government administration, finance, health, managed service providers
Target regions
North America, Global
Detection rules
9
Indicators of compromise
23

How Active Exploitation of Cisco Unified Communications Manager works

Two critical Cisco vulnerabilities are under active exploitation: CVE-2026-20230, an unauthenticated SSRF in Unified Communications Manager's WebDialer service abused via a rogue Apache Axis service and JSP file-write to achieve root, and CVE-2026-20245, a Catalyst SD-WAN Manager privilege-escalation flaw exploited as a zero-day since early 2026 by a threat actor who escalated a compromised vmanage-admin account to root via a malicious CSV upload, creating a rogue root account named troot at a service-provider SD-WAN fabric.

CVE-2026-20230 is a CVSS 8.6 server-side request forgery vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), caused by improper input validation of HTTP requests processed by the WebDialer service. WebDialer is a click-to-call feature that is disabled by default but commonly enabled by organizations integrating desktop/web dialing. When enabled, an unauthenticated remote attacker can send crafted HTTP requests that force the server to make unintended internal requests, which SSD Secure Disclosure describes as leveraging the WebDialer component to resolve the true hostname of the target and ultimately write arbitrary files to the underlying operating system. Reported exploitation observed by Defused Cyber uses this file-write primitive to deploy a rogue Apache Axis service and drop a first-stage JSP file capable of executing commands, followed by a second-stage web shell placed under the Axis2 web application path (/platform-services/axis2-web/), giving the attacker a durable, authenticated code-execution foothold that can be escalated to root. Cisco shipped a fix on June 3, 2026 (Unified CM/Unified CM SME 14SU6 and 15SU5); a public PoC surfaced at disclosure, and active in-the-wild exploitation was confirmed roughly three weeks later, prompting CISA to add the CVE to the Known Exploited Vulnerabilities (KEV) catalog on June 25, 2026.

CVE-2026-20245 is a CVSS 7.8 privilege-escalation vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator, caused by insufficient validation of user-supplied input in a file-upload code path. An authenticated local attacker (i.e., one already holding valid vmanage-admin or admin credentials, which normally lack root shell access) can supply a crafted file to execute arbitrary commands as root. Mandiant's investigation, published June 25, 2026, documents real-world zero-day exploitation beginning in early 2026 -- months before Cisco's official June disclosure -- against a service provider's SD-WAN infrastructure, giving the threat actor visibility across the provider's entire corporate internet traffic. The observed intrusion chain began with unauthorized peering connections into the SD-WAN fabric in late 2025/January 2026 (potentially via separate peering-authentication-bypass flaws CVE-2026-20127 and CVE-2026-20182), followed in March 2026 by SSH access using a compromised vmanage-admin account, a password change to access the web UI, exfiltration of SD-WAN fabric configuration, and a password reset to cover tracks. In April 2026 the actor exploited CVE-2026-20245 by issuing the Viptela CLI command `request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0`, where evil_tenant.csv contained a shell payload that backed up /usr/share/viptela/vbond_vsmart_tenant_list, /etc/passwd, and /etc/shadow, then appended a UID-0 account named troot to /etc/passwd and /etc/shadow. The actor subsequently accessed the troot account from the admin account via `su`. Post-exploitation, the actor performed methodical anti-forensic cleanup: deleting the CSV payload and backup files, restoring modified configuration state, resetting the admin password to its original value, and running a validation script that checks whether every artifact of the intrusion (the CSV, the backup files, and the troot account) has been fully removed -- indicating a disciplined, nation-state-caliber operator. This is Cisco's sixth SD-WAN vulnerability confirmed under active attack since early 2026 and the second SD-WAN zero-day exploited in a two-month span, underscoring SD-WAN edge infrastructure as a persistent, high-value target for espionage-motivated intrusion sets. Fixed releases are 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2 or later.

MITRE ATT&CK techniques used in TL-2026-1025

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery; T1083 File and Directory Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts; T1543 Create or Modify System Process

Defense Evasion

T1070.004 File Deletion; T1078 Valid Accounts

Command and Control

T1071.001 Web Protocols

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

persistence

T1098 Account Manipulation

Persistence

T1136.001 Local Account; T1505.003 Web Shell

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1531 Account Access Removal

Credential Access

T1552.001 Credentials In Files

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Affected products and versions in Active Exploitation of Cisco Unified Communications Manager

  • Cisco — Unified Communications Manager (Unified CM)
    Vulnerable versions: releases prior to 14SU6
    Fixed in: 14SU6
  • Cisco — Unified Communications Manager Session Management Edition (Unified CM SME)
    Vulnerable versions: releases prior to 15SU5
    Fixed in: 15SU5
  • Cisco — Catalyst SD-WAN Manager
    Vulnerable versions: releases prior to fixed versions
    Fixed in: 20.9.9.2; 20.12.7.2; 20.15.4.5; 20.15.5.3; 20.18.3.1; 26.1.1.2
  • Cisco — Catalyst SD-WAN Controller
    Vulnerable versions: releases prior to fixed versions
    Fixed in: 20.9.9.2; 20.12.7.2; 20.15.4.5; 20.15.5.3; 20.18.3.1; 26.1.1.2
  • Cisco — Catalyst SD-WAN Validator
    Vulnerable versions: releases prior to fixed versions
    Fixed in: 20.9.9.2; 20.12.7.2; 20.15.4.5; 20.15.5.3; 20.18.3.1; 26.1.1.2

Remediation for Active Exploitation of Cisco Unified Communications Manager

Patches

  • Apply Cisco Security Advisory cisco-sa-cucm-ssrf-cXPnHcW: upgrade Unified CM / Unified CM SME to 14SU6 or 15SU5
  • Apply Cisco Security Advisory cisco-sa-sdwan-privesc-4uxFrdzx: upgrade Catalyst SD-WAN Controller/Manager/Validator to 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2+

Immediate actions

  • Disable the WebDialer feature on Cisco Unified CM / Unified CM SME if not required for click-to-call functionality
  • Audit and disable unused vmanage-admin/admin CLI file-upload paths (request tenant-upload) on Catalyst SD-WAN Manager
  • Search /etc/passwd and /etc/shadow on all Catalyst SD-WAN Controller/Manager/Validator nodes for an unauthorized UID-0 account named troot
  • Review /var/log/scripts.log and auth.log for tenant-upload script execution and unexpected su sessions to troot
  • Block outbound connections from SD-WAN management infrastructure to the identified threat-actor IP ranges

Workarounds

  • Disable WebDialer service on Unified CM/Unified CM SME (Cisco Unified CM Administration > Cisco Unified Serviceability > Control Center - Feature Services > CTI Services)
  • Restrict CLI access to Catalyst SD-WAN Manager to trusted administrators only pending patch deployment

Longer-term hardening

  • Deploy EDR/host-based file-integrity monitoring on Unified CM and SD-WAN Manager appliances to detect unauthorized JSP/webshell writes
  • Enforce MFA and IP allow-listing for vmanage-admin and admin account access
  • Segment SD-WAN management-plane peering from general corporate network access
  • Rotate all administrative credentials and SSH keys for affected SD-WAN and UCM infrastructure
  • Establish periodic KEV-catalog monitoring for Cisco collaboration and SD-WAN product advisories

CVEs associated with Active Exploitation of Cisco Unified Communications Manager

CVE-2026-20230, CVE-2026-20245, CVE-2026-20127, CVE-2026-20182

Weaknesses (CWE) in Active Exploitation of Cisco Unified Communications Manager

CWE-918, CWE-20, CWE-269

Timeline of Active Exploitation of Cisco Unified Communications Manager

  • Unauthorized peering connections established within the Catalyst SD-WAN fabric, possibly leveraging separate peering-authentication-bypass flaws (CVE-2026-20127 / CVE-2026-20182), marking the earliest observed threat-actor foothold.
  • Threat actor authenticates via SSH using the compromised vmanage-admin account (01:31:48 UTC), changes the admin password to access the web interface, and begins exfiltrating SD-WAN fabric configuration data.
  • Threat actor exploits CVE-2026-20245 as a zero-day via the CLI command 'request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0', executing a malicious payload that creates the rogue root account 'troot' by appending entries to /etc/passwd and /etc/shadow.
  • Actor accesses the troot account from admin via su, then performs anti-forensic cleanup: deleting the CSV payload and backup files, restoring modified configuration state, resetting the admin password to its original value, and running a validation script to confirm all intrusion artifacts were removed.
  • Cisco releases fixes for CVE-2026-20230 (Unified CM/Unified CM SME 14SU6, 15SU5) and CVE-2026-20245 (Catalyst SD-WAN Controller/Manager/Validator 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2) alongside public security advisories cisco-sa-cucm-ssrf-cXPnHcW and cisco-sa-sdwan-privesc-4uxFrdzx.
  • Public proof-of-concept exploit code for CVE-2026-20230's file-write-to-root chain becomes available shortly after disclosure.
  • Defused Cyber observes active exploitation of CVE-2026-20230 in the wild over the weekend preceding the June 24 Register report, involving a rogue Apache Axis service and JSP web-shell deployment.
  • The Register publishes 'The hits keep on coming for Cisco vulnerabilities,' consolidating active-exploitation reporting on both CVE-2026-20230 and CVE-2026-20245.
  • Mandiant (Google Threat Intelligence) publishes a detailed technical writeup of the CVE-2026-20245 zero-day intrusion at a service-provider SD-WAN environment, including the full command sequence, IOCs, and anti-forensic tradecraft.
  • CISA adds both CVE-2026-20230 and CVE-2026-20245 to the Known Exploited Vulnerabilities (KEV) catalog.

Sources cited for Active Exploitation of Cisco Unified Communications Manager

Detection coverage for TL-2026-1025

As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1025 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats