CVE-2026-20230: Cisco Unified Communications Manager WebDialer SSRF Actively Exploited to Drop Tor-Routed JSP Webshells via Rogue Apache Axis Service, CISA Sets June 28 Deadline
CVE-2026-20230 (TL-2026-1236) is a critical-severity software vulnerability scored CVSS 8.6, first published 2026-07-11. It has no confirmed attribution, affects Cisco Unified Communications Manager (Unified CM), references 1 CVE (CVE-2026-20230), maps to 13 MITRE ATT&CK techniques (T1021, T1036, T1053), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-1236
- Threat ID
- TL-2026-1236
- Severity
- CRITICAL
- CVSS
- 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, government administration, enterprise communications, critical infrastructure, federal civilian agencies
- Target regions
- united states of america, Asia, North America, Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in CVE-2026-20230
Malware and tooling: three-stage JSP command-execution webshell, HORKimhab/CVE-2026-20230, HalilDeniz/CVE-2026-20230-Scanner, NodeZero Rapid Response, Tor-routed automated exploitation sweeps
CISA added CVE-2026-20230, a critical unauthenticated SSRF vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), to its Known Exploited Vulnerabilities catalog after security firm Defused observed active exploitation. Attackers abuse the WebDialer service to force an internal-proxy trust bypass, first fingerprinting targets with simple file writes and then escalating to automated Tor-routed sweeps that deploy a rogue Apache Axis service and drop three-stage JSP command-execution webshells under /platform-services/axis2-web/, a path that can be leveraged toward root-level compromise via cron/startup mechanisms. Federal agencies face a June 28, 2026 remediation deadline under BOD 26-04; the responsible threat actor is unknown, and Shadowserver tracks 200+ internet-exposed Unified CM instances.
How CVE-2026-20230 works
CVE-2026-20230 is a CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N) server-side request forgery vulnerability (CWE-918) in the WebDialer web service component of Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), also affecting legacy CallManager deployments carrying the same code lineage. Improper validation of specific HTTP request parameters allows an unauthenticated, remote attacker to force the WebDialer application to act as an internal proxy, issuing requests to loopback (127.0.0.1) interfaces and internal IPC sockets that implicitly trust local-origin traffic. By chaining this trust-boundary bypass with access to internal administrative APIs, the attacker can write arbitrary text and file:// payloads to sensitive filesystem locations, including system initialization directories and cron.d job directories. Because cron and startup scripts execute automatically with root privileges, a maliciously placed file in these locations provides a path to full root-level compromise. Exploitation requires the WebDialer service to be enabled; it is disabled by default, which limits exposure to organizations that have activated the feature for click-to-dial functionality.
Cisco patched the flaw on June 3, 2026 with a public PoC exploit surfacing within 24-48 hours (June 4-5, 2026) and no evidence of in-the-wild exploitation at disclosure time. Threat detection firm Defused subsequently observed real-world exploitation beginning the weekend of June 21-22, 2026, describing early activity as originating 'from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys' — payloads consistent with the publicly leaked PoC rather than a bespoke, more sophisticated exploit, used initially to fingerprint vulnerable devices by writing a test file such as /tmp/cve-2026-20230-test.txt. By June 24, 2026, Defused and independent researchers (including SSD Secure, which published its own technical PoC write-up on June 23, 2026) documented an escalation: automated, Tor-routed reconnaissance sweeps that abuse the WebDialer SSRF to deploy a rogue Apache Axis service, which is then used to write a second-stage JSP command-execution webshell to disk under the /platform-services/axis2-web/ directory — a three-stage chain (SSRF trigger -> rogue Axis service deployment -> JSP webshell drop) that grants attackers persistent remote command execution independent of the original SSRF vector and that a vendor patch alone does not evict once deployed.
CISA added the CVE to its Known Exploited Vulnerabilities catalog on June 25, 2026, and — citing Binding Operational Directive BOD 26-04 (Prioritizing Security Updates Based on Risk) — set a June 28, 2026 remediation deadline for federal civilian agencies, requiring patching, mitigation, or discontinued use of the product. Cisco updated its advisory on July 1-2, 2026 to formally confirm active exploitation. Shadowserver telemetry reports over 200 Cisco Unified CM instances directly exposed to the internet, concentrated in Asia and North America, underscoring a substantial unauthenticated attack surface. Public offensive tooling proliferated quickly: the HalilDeniz/CVE-2026-20230-Scanner and HORKimhab/CVE-2026-20230 GitHub repositories both provide validation/exploitation scripts, and Horizon3.ai's NodeZero Rapid Response module offers automated safe verification for defenders. The unauthenticated network attack vector, absence of user interaction, critical infrastructure use case (unified communications/VoIP), webshell persistence independent of the initial vulnerability, and existence of multiple public, weaponized PoCs make this a high-priority remediation and incident-response target for any organization running affected Unified CM/SME deployments with WebDialer enabled — patching alone does not remove webshells already dropped, so post-compromise forensic review is required even after upgrading.
MITRE ATT&CK techniques used in TL-2026-1236
Lateral Movement
Defense Evasion
Persistence
T1053 Scheduled Task/Job; T1505 Server Software Component
Privilege Escalation
T1053 Scheduled Task/Job; T1548 Abuse Elevation Control Mechanism
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery
command-and-control
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
Reconnaissance
Affected products and versions in CVE-2026-20230
- Cisco — Unified Communications Manager (Unified CM)
Vulnerable versions: pre-12.5SU9; Release 14 pre-14SU6; Release 15 pre-15SU5
Fixed in: 12.5SU9; 14SU6; 15SU5; interim COP patch (15.x pending 15SU5 GA) - Cisco — Unified Communications Manager Session Management Edition (Unified CM SME)
Vulnerable versions: pre-14SU6; pre-15SU5
Fixed in: 14SU6; 15SU5; interim COP patch
Remediation for CVE-2026-20230
Patches
- Cisco Unified CM / Unified CM SME Release 14: upgrade to 14SU6
- Cisco Unified CM / Unified CM SME Release 15: upgrade to 15SU5 or apply interim COP patch
- Cisco Unified CM Release 12.5: upgrade to 12.5SU9 (pre-12.5SU9 builds vulnerable per third-party exploit analysis)
Immediate actions
- Disable the Cisco WebDialer Web Service via Unified CM Administration -> Unified Serviceability -> Service Activation if patching cannot occur immediately
- Apply Cisco's security patch released June 3, 2026 (14SU6 / 15SU5 or interim COP)
- Audit Unified CM access/HTTP logs for unexpected requests to WebDialer endpoints, especially from external IP addresses and Tor exit-node ranges
- Search the filesystem for unexpected files, especially in directories writable by the web service account, cron.d/startup locations, and /platform-services/axis2-web/
- Inspect for unauthorized/rogue Apache Axis service instances and unexplained JSP files as evidence of webshell persistence that survives patching
- Treat any host with evidence of exploitation as compromised and rebuild/re-image rather than relying on patch-only remediation
Workarounds
- Disable the WebDialer service entirely if the click-to-dial feature is not required (WebDialer is disabled by default)
- No permanent workaround exists other than disabling WebDialer or patching per Cisco's advisory; post-exploitation webshell cleanup is required separately from patching
Longer-term hardening
- Upgrade all Unified CM and Unified CM SME deployments to 14SU6 or later, or 15SU5 or later
- Restrict network exposure of Unified CM/WebDialer interfaces to trusted management networks only; remove from direct internet exposure (Shadowserver tracks 200+ exposed instances)
- Implement continuous monitoring for anomalous cron/startup file modifications and unexpected Apache Axis service deployments on VoIP infrastructure
- Track CISA KEV catalog additions and BOD 26-04 deadlines for federal or federally-adjacent environments
- Use vendor or third-party safe-verification tooling (e.g., Horizon3.ai NodeZero Rapid Response) to confirm remediation and absence of webshell artifacts
CVEs associated with CVE-2026-20230
Weaknesses (CWE) in CVE-2026-20230
CWE-918
Timeline of CVE-2026-20230
- Cisco publishes advisory cisco-sa-cucm-ssrf-cXPnHcW and releases patched Unified CM/SME builds for CVE-2026-20230; no active exploitation observed at disclosure.
- A fully functional, weaponized PoC exploit is publicly leaked and distributed across open-source security repositories, roughly 24 hours after disclosure.
- Public PoC exploit code is broadly available, prompting Cisco to issue a follow-up warning (BleepingComputer).
- Third-party technical exploit-chain analysis published detailing the SSRF-to-internal-proxy-to-file-write-to-root chain.
- Threat detection firm Defused begins observing real-world exploitation attempts against decoy Unified CM instances, originating from a single source using the leaked, unvetted PoC and writing fingerprint test files.
- SSD Secure publishes an independent technical write-up and proof-of-concept for CVE-2026-20230.
- Defused and multiple outlets (The Hacker News, Help Net Security, TechTimes, BleepingComputer) disclose escalation to automated, Tor-routed exploitation sweeps deploying a rogue Apache Axis service and dropping three-stage JSP webshells under /platform-services/axis2-web/.
- CISA adds CVE-2026-20230 to the Known Exploited Vulnerabilities (KEV) catalog.
- BleepingComputer reports CISA's urgent remediation deadline for federal agencies under BOD 26-04.
- Federal civilian agency remediation deadline under Binding Operational Directive BOD 26-04.
- Cisco updates its security advisory to formally confirm active exploitation of CVE-2026-20230 in the wild.
- Cisco formally confirms in-the-wild exploitation and warns that patching alone does not remove previously dropped webshells, requiring separate incident-response cleanup.
Sources cited for CVE-2026-20230
- CISA Sets Urgent Deadline to Fix Cisco Flaw Exploited in Attacks
- Cisco warns of critical Unified CM flaw with PoC exploit code
- Cisco Unified CM SME flaw CVE-2026-20230 now exploited in attacks
- Cisco finally confirms attackers exploiting Unified CM flaw
- Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
- Cisco Security Advisory (cisco-sa-cucm-ssrf-cXPnHcW)
- CVE-2026-20230 Detail - NVD
- CISA Known Exploited Vulnerabilities Catalog
- CVE-2026-20230 Cisco Unified CM SSRF - Exploit Chain Analysis
- CVE-2026-20230: Cisco Unified CM SSRF | Horizon3.ai Attack Research
- Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
- Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)
- Cisco Unified CM CVE-2026-20230: Webshell Drops Confirmed, Patch Alone Won't Evict Attackers
- Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
- GitHub - HalilDeniz/CVE-2026-20230-Scanner
Threats related to CVE-2026-20230
- Cisco Unified CM / Unified CM SME SSRF Vulnerability (CVE-2026-20230) — WebDialer File-Write to Root, Actively Exploited, Added to CISA KEV
- CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root)
- CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploited
- Cisco Unified CM WebDialer SSRF (CVE-2026-20230) — Unauthenticated SSRF Chained to Arbitrary File Write Enabling Root Compromise; Public PoC Available
- CVE-2026-5027: Path Traversal Arbitrary File Write in Langflow AI Dev Platform (upload_user_file) Exploited in the Wild for Unauthenticated RCE
- CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise
Detection coverage for TL-2026-1236
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1236 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.