Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245) — Threadlinqs Intelligence
As of 2026-07-01, Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245) is a critical-severity vulnerability threat attributed to Unknown (Mandiant-tracked, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1025 · Severity: CRITICAL · CVSS: 8.6 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Unknown (Mandiant-tracked · ESPIONAGE
Two critical Cisco vulnerabilities are under active exploitation: CVE-2026-20230, an unauthenticated SSRF in Unified Communications Manager's WebDialer service abused via a rogue Apache Axis service
CVE-2026-20230 is a CVSS 8.6 server-side request forgery vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), caused by improper input validation of HTTP requests processed by the WebDialer service. WebDialer is a click-to-call feature that is disabled by default but commonly enabled by organizations integrating desktop/web dialing. When enabled, an unauthenticated remote attacker can send crafted HTTP requests that force the server to make unintended internal requests, which SSD Secure Disclosure describes as leveraging the WebDialer component to resolve the true hostname of the target and ultimately write arbitrary files to the underlying operating system. Reported exploitation observed by Defused Cyber uses this file-write primitive to deploy a rogue Apache Axis service and drop a first-stage JSP file capable of executing commands, followed by a second-stage web shell placed under the Axis2 web application path (/platform-services/axis2-web/), giving the attacker a durable, authenticated code-execution foothold that can be escalated to root. Cisco shipped a fix on June 3, 2026 (Unified CM/Unified CM SME 14SU6 and 15SU5); a public PoC surfaced at disclosure, and active in-the-wild exploitation was confirmed roughly three weeks later, prompting CISA to add the CVE to the Known Exploited Vulnerabilities (KEV) catalog on June 25, 2026.
CVE-2026-20245 is a CVSS 7.8 privilege-escalation vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator, caused by insufficient validation of user-supplied input in a file-upload code path. An authenticated local attacker (i.e., one already holding valid vmanage-admin or admin credentials, which normally lack root shell access) can supply a crafted file to execute arbitrary commands as root. Mandiant's investigation, published June 25, 2026, documents real-world zero-day exploitation beginning in early 2026 -- months before Cisco's official June disclosure -- against a service provider's SD-WAN infrastructure, giving the threat actor visibility across the provider's entire corporate internet traffic. The observed intrusion chain began with unauthorized peering connections into the SD-WAN fabric in late 2025/January 2026 (potentially via separate peering-authentication-bypass flaws CVE-2026-20127 and CVE-2026-20182), followed in March 2026 by SSH access using a compromised vmanage-admin account, a password change to access the web UI, exfiltration of SD-WAN fabric configuration, and a password reset to cover tracks. In April 2026 the actor exploited CVE-2026-20245 by issuing the Viptela CLI command `request tenant-upload tenant-list /home/admin/evil_tenant.csv vpn 0`, where evil_tenant.csv contained a shell payload that backed up /usr/share/viptela/vbond_vsmart_tenant_list, /etc/passwd, and /etc/shadow, then appended a UID-0 account named troot to /etc/passwd and /etc/shadow. The actor subsequently accessed the troot account from the admin account via `su`. Post-exploitation, the actor performed methodical anti-forensic cleanup: deleting the CSV payload and backup files, restoring modified configuration state, resetting the admin password to its original value, and running a validation script that checks whether every artifact of the intrusion (the CSV, the backup files, and the troot account) has been fully removed -- indicating a disciplined, nation-state-caliber operator. This is Cisco's sixth SD-WAN vulnerability confirmed under active attack since early 2026 and the second SD-WAN zero-day exploited in a two-month span, underscoring SD-WAN edge infrastructure as a persistent, high-value target for espionage-motivated intrusion sets. Fixed releases are 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2 or later.
Weaknesses (CWE)
CWE-918, CWE-20, CWE-269
Target sectors: telecoms, government administration, finance, health, managed service providers
Target regions: North America, Global
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20230, CVE-2026-20245, CVE-2026-20127, CVE-2026-20182, T1190, T1078, T1059, T1059.004, T1505.003, T1136.001, T1068, T1078, T1543, T1070.004