Hackers are actively exploiting a critical vulnerability in Cisco’s Unified Communications Manager (Unified CM). Identified as CVE-2026-20230, the server-side request forgery (SSRF) flaw allows unauthenticated remote attackers to write arbitrary files. This exploit enables attackers to escalate privileges to root on affected systems.

Cisco released patches for the vulnerability on June 3, 2026. No active exploits existed at the time of the initial patch release. Security firm Defused recently observed exploitation activity using a proof-of-concept to write test files onto vulnerable devices.

The flaw specifically impacts systems with the WebDialer service enabled. This service remains turned off by default in standard configurations.

Cisco reports no available workarounds for the issue. The company urges customers to upgrade to fixed software releases immediately. These attacks emerged just weeks after the patch became available, necessitating urgent organizational updates to prevent system compromise.