CVE-2026-20230: Cisco Unified Communications Manager WebDialer SSRF Actively Exploited to Drop Tor-Routed JSP Webshells via Rogue Apache Axis Service, CISA Sets June 28 Deadline — Threadlinqs Intelligence
As of 2026-07-11, CVE-2026-20230: Cisco Unified Communications Manager WebDialer SSRF Actively Exploited to Drop Tor-Routed JSP Webshells via Rogue Apache Axis Service, CISA Sets June 28 Deadline is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1236 · Severity: CRITICAL · CVSS: 8.6 · Status: ACTIVE · Category: VULNERABILITY
CISA added CVE-2026-20230, a critical unauthenticated SSRF vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), to its Known Exploited
CVE-2026-20230 is a CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N) server-side request forgery vulnerability (CWE-918) in the WebDialer web service component of Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME), also affecting legacy CallManager deployments carrying the same code lineage. Improper validation of specific HTTP request parameters allows an unauthenticated, remote attacker to force the WebDialer application to act as an internal proxy, issuing requests to loopback (127.0.0.1) interfaces and internal IPC sockets that implicitly trust local-origin traffic. By chaining this trust-boundary bypass with access to internal administrative APIs, the attacker can write arbitrary text and file:// payloads to sensitive filesystem locations, including system initialization directories and cron.d job directories. Because cron and startup scripts execute automatically with root privileges, a maliciously placed file in these locations provides a path to full root-level compromise. Exploitation requires the WebDialer service to be enabled; it is disabled by default, which limits exposure to organizations that have activated the feature for click-to-dial functionality.
Cisco patched the flaw on June 3, 2026 with a public PoC exploit surfacing within 24-48 hours (June 4-5, 2026) and no evidence of in-the-wild exploitation at disclosure time. Threat detection firm Defused subsequently observed real-world exploitation beginning the weekend of June 21-22, 2026, describing early activity as originating 'from a single source using an unvetted PoC, with genuinely-formatted file:// file-write payloads landing on our decoys' — payloads consistent with the publicly leaked PoC rather than a bespoke, more sophisticated exploit, used initially to fingerprint vulnerable devices by writing a test file such as /tmp/cve-2026-20230-test.txt. By June 24, 2026, Defused and independent researchers (including SSD Secure, which published its own technical PoC write-up on June 23, 2026) documented an escalation: automated, Tor-routed reconnaissance sweeps that abuse the WebDialer SSRF to deploy a rogue Apache Axis service, which is then used to write a second-stage JSP command-execution webshell to disk under the /platform-services/axis2-web/ directory — a three-stage chain (SSRF trigger -> rogue Axis service deployment -> JSP webshell drop) that grants attackers persistent remote command execution independent of the original SSRF vector and that a vendor patch alone does not evict once deployed.
CISA added the CVE to its Known Exploited Vulnerabilities catalog on June 25, 2026, and — citing Binding Operational Directive BOD 26-04 (Prioritizing Security Updates Based on Risk) — set a June 28, 2026 remediation deadline for federal civilian agencies, requiring patching, mitigation, or discontinued use of the product. Cisco updated its advisory on July 1-2, 2026 to formally confirm active exploitation. Shadowserver telemetry reports over 200 Cisco Unified CM instances directly exposed to the internet, concentrated in Asia and North America, underscoring a substantial unauthenticated attack surface. Public offensive tooling proliferated quickly: the HalilDeniz/CVE-2026-20230-Scanner and HORKimhab/CVE-2026-20230 GitHub repositories both provide validation/exploitation scripts, and Horizon3.ai's NodeZero Rapid Response module offers automated safe verification for defenders. The unauthenticated network attack vector, absence of user interaction, critical infrastructure use case (unified communications/VoIP), webshell persistence independent of the initial vulnerability, and existence of multiple public, weaponized PoCs make this a high-priority remediation and incident-response target for any organization running affected Unified CM/SME deployments with WebDialer enabled — patching alone does not remove webshells already dropped, so post-compromise forensic review is required even after upgrading.
Target sectors: telecoms, government administration, enterprise communications, critical infrastructure, federal civilian agencies
Target regions: united states of america, Asia, North America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20230, T1595, T1588, T1190, T1059, T1053, T1505, T1053, T1548, T1090, T1036