Cisco warns of critical Unified CM flaw with PoC exploit code
Cisco has released security updates for a critical vulnerability in Unified Communications Manager (Unified CM) that could allow remote attackers to gain root-level privileges. Tracked as CVE-2026-20230, the flaw stems from a server-side request forgery (SSRF) issue exploitable through crafted HTTP requests, enabling attackers to write files to the underlying operating system and potentially escalate to root. Cisco confirmed that proof-of-concept exploit code is publicly available, but stated there is no evidence of active exploitation. The vulnerability only affects systems with the WebDialer service enabled, which is disabled by default. Administrators are urged to apply Unified CM 14SU6 or 15SU5, or disable WebDialer until patches can be installed.
What this means for your organisation
Telephony platforms are often treated as infrastructure rather than as IT systems with the same patching requirements. Root access on a Unified CM gives an attacker both interception opportunities and a solid foothold in the internal network. When proof-of-concept code is public, the distance from knowledge to exploitation is short, even if no attacks have been seen yet.
Berigo recommends
- Check whether WebDialer is enabled and disable the service if it is not in use.
- Upgrade to Unified CM 14SU6 or 15SU5 within your deadline for critical vulnerabilities.
- Restrict administrative access to the telephony platform to defined network segments.
- Include telephony and meeting room equipment in ordinary vulnerability management rather than as an exception.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch