Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
A recently revealed serious security vulnerability affecting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) has been exploited by threat actors.
The vulnerability, known as CVE-2026-20230 (CVSS score: 8.6), is a case of incorrect input validation for particular HTTP requests that may enable server-side request forgery (SSRF) attacks through an impacted device by an unauthenticated, remote attacker.
According to a Cisco advisory issued earlier this month, "an attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device." If the exploit is successful, the attacker may be able to write files to the underlying operating system that they can then use to elevate to root.
...


