CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise — Threadlinqs Intelligence
As of 2026-07-02, CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1070 · Severity: HIGH · CVSS: 8.6 · Status: ACTIVE · Category: VULNERABILITY
Cisco confirmed on July 2, 2026 active in-the-wild exploitation of CVE-2026-20230, a CVSS 8.6 unauthenticated SSRF vulnerability in the WebDialer service of Cisco Unified Communications Manager
CVE-2026-20230 is a Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in the WebDialer service of Cisco Unified Communications Manager (Unified CM, formerly CallManager) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). The flaw stems from improper input validation of specific HTTP requests processed by WebDialer, allowing an unauthenticated, remote attacker to submit crafted HTTP requests that force the application to make unintended server-side requests. When WebDialer accepts file:// scheme payloads, an attacker can coerce the application into writing arbitrary files to the underlying operating system.
Cisco publicly disclosed and patched the vulnerability on June 3, 2026 (advisory cisco-sa-cucm-ssrf-cXPnHcW), at the time noting that proof-of-concept code existed but stating it had no evidence of active exploitation. Within roughly three weeks, threat intelligence firm Defused observed the vulnerability being actively exploited in the wild beginning the weekend of June 21-22, 2026, using file:// SSRF payloads to plant files on targeted Unified CM appliances. Independent researchers at SSD Secure published a technical writeup and working PoC on June 23, 2026, and public exploitation was reportedly weaponized within 24 hours of the technical details becoming available.
The observed attack chain begins with the unauthenticated SSRF against the WebDialer endpoint, which is used to deploy a rogue Apache Axis service on the appliance. That rogue Axis service is then abused to write a first-stage JSP file-writer web shell to a web-accessible directory, which in turn is used to drop a second-stage command-execution shell, giving the attacker persistent remote code execution. Cisco assessed the overall impact as Critical (despite the CVSS base score of 8.6, which nominally maps to High) because successful exploitation can be leveraged to elevate privileges to root on the underlying appliance operating system, resulting in complete compromise of the Unified CM instance including call routing, directory, and telephony control functions.
Exploitation requires that the WebDialer feature be enabled; WebDialer is disabled by default, meaning organizations that have not enabled the click-to-dial feature are not exposed. However, Shadowserver scanning identified more than 200 Cisco Unified CM instances exposed directly to the internet, concentrated in Asia and North America, with no reliable telemetry yet available on how many have applied the fix. CISA added CVE-2026-20230 to its Known Exploited Vulnerabilities (KEV) catalog on or around June 25, 2026 and, per Binding Operational Directive (BOD) 26-04, set an urgent remediation deadline of June 28, 2026 for federal civilian agencies. Cisco confirmed active exploitation on July 2, 2026 and released an updated fix in the September 2026 Cumulative Object Package (COP) for versions 14SU6 and 15SU5.
Because Unified CM is core telephony/UC infrastructure typically deployed on-premises and often internet-facing for remote worker or SIP trunk connectivity, a root-level compromise creates risk of call interception, toll fraud, lateral movement into the broader enterprise voice/video environment, and use of the appliance as a foothold for further network intrusion.
Target sectors: telecoms, enterprise-voip, government administration, finance, health, critical-infrastructure
Target regions: Asia, North America, Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-20230, T1190, T1505, T1059, T1505, T1505, T1068, T1036, T1610, T1046, T1518