threat-intel
In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
Critical
Summary
A critical vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager (CUCM) has been rapidly weaponized by attackers within 24 hours of a proof-of-concept release. The SSRF flaw allows unauthenticated remote attackers to gain root access, potentially leading to full control of vulnerable systems. Organizations using CUCM with the WebDialer enabled are urged to patch immediately to mitigate this high-severity risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
