Web_Logo
Remote Support
Security Alert: Cisco Unified CM Flaw Actively Exploited — Patch Before June 28
Home » Security Alerts  »  Security Alert: Cisco Unified CM Flaw Actively Exploited — Patch Before June 28

Security Alert: Cisco Unified CM Flaw Actively Exploited — Patch Before June 28

A critical vulnerability in Cisco's Unified Communications Manager is being actively exploited right now, with attackers installing hidden backdoors on affected systems. If your business uses Cisco's phone or communications platform, this requires urgent attention — the patch deadline is tomorrow, 28 June 2026.

  • What it is: CVE-2026-20230 is a server-side request forgery (SSRF) flaw in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition. It allows an unauthenticated attacker to send a specially crafted request and gain root-level access to the system.
  • Who is affected: Organisations running Cisco Unified CM with the WebDialer feature enabled. WebDialer is used for click-to-call functionality and is off by default, but many businesses enable it during setup. If you're unsure whether WebDialer is enabled in your environment, assume it may be and act accordingly.
  • What the risk is: Attackers have been actively exploiting this vulnerability since the weekend of 21–22 June 2026, deploying webshells (hidden backdoors) through automated Tor-based scans. A successful attack gives the attacker full control of the communications server. CISA has added this to its Known Exploited Vulnerabilities catalog and set a mandatory patch deadline of 28 June 2026 for US federal agencies.
  • What action is needed: Apply Cisco's patch immediately — it was released on 3 June 2026. If patching cannot happen today, disable WebDialer as a temporary measure to remove the attack surface. Check systems for signs of compromise, including unexpected files or new services in the WebDialer directory.

If your organisation uses Cisco Unified Communications Manager, we recommend treating this as an urgent priority. Contact your IT provider today to confirm patch status. Sources: BleepingComputer, CISA KEV Catalog, Help Net Security.