Cisco patches critical Unified CM flaw that could grant root access via SSRF

1 min read
Source: BleepingComputer
Cisco patches critical Unified CM flaw that could grant root access via SSRF
Photo: BleepingComputer
TL;DR Summary

Cisco released security updates for a critical flaw in Unified CM (CVE-2026-20230) that can be exploited remotely through SSRF to write files and escalate to root. A public PoC exists, but there is no evidence of active exploitation yet. The vulnerability affects systems with WebDialer enabled (WebDialer is disabled by default); admins are urged to upgrade to 14SU6 or 15SU5 or disable WebDialer as a temporary measure until patches are applied.

Share this article

Reading Insights

Total Reads

0

Unique Readers

6

Time Saved

3 min

vs 4 min read

Condensed

90%

71271 words

Want the full story? Read the original article

Read on BleepingComputer