Cisco Unified CM SSRF Flaw Under Active Exploitation After PoC Enables File Write to Root
Threat actors are actively exploiting a critical SSRF flaw in Cisco Unified Communications Manager, allowing unauthenticated attackers to write files to the underlying OS and escalate to root. GCC enterprises using Unified CM should patch to versions 14SU6 or 15SU5 immediately.

Network engineer monitoring active exploitation alerts representing the Cisco Unified CM CVE-2026-20230 SSRF vulnerability under attack in 2026
Cisco Unified CM SSRF Vulnerability Moves to Active Exploitation After PoC Enables File-Write Path to Root
Threat actors have begun actively exploiting a critical vulnerability in Cisco Unified Communications Manager and Unified Communications Manager Session Management Edition, less than three weeks after Cisco published its advisory and within days of a working proof-of-concept becoming available. The flaw, tracked as CVE-2026-20230 with a CVSS score of 8.6, allows an unauthenticated, remote attacker to conduct server-side request forgery attacks through the affected device and write files to the underlying operating system, which can subsequently be leveraged to escalate privileges to root.
Defused Cyber confirmed active exploitation in a post on X earlier this week, noting it was observing exploitation from a single source using an unvetted proof-of-concept, with file-write payloads landing on its decoys. SSD Secure Disclosure has since published additional technical detail, describing the flaw as enabling unauthenticated attackers to achieve code execution by leveraging the WebDialer component to obtain the true hostname of the target before writing malicious files.
Technical Detail
The vulnerability resides in improper input validation for specific HTTP requests. A crafted HTTP request sent to an affected device can trigger a file-write operation on the underlying operating system. According to Cisco's advisory, the written files can be used to subsequently elevate privileges to root.
One critical operational detail: the WebDialer service must be enabled for the vulnerability to be exploitable. WebDialer is disabled by default in Cisco Unified CM. Administrators should verify the current status of the Cisco WebDialer Web Service in the Control Centre Feature Services section of the Unified Serviceability interface. If the status shows as Started, the deployment is exposed.
Cisco has released patches in Unified CM and Unified CM SME versions 14SU6 and 15SU5. If immediate patching is not possible, disabling the WebDialer service is the recommended interim mitigation.
Why GCC Enterprises Should Act Now
Cisco Unified Communications Manager is among the most widely deployed enterprise communications platforms across GCC government, financial services, and large enterprise environments. The active exploitation of this flaw, combined with a publicly available proof-of-concept and a file-write-to-root attack chain, creates a narrow patching window before opportunistic attackers begin scanning for exposed instances at scale.
This follows a pattern that has defined enterprise vulnerability exploitation in 2026: a vendor publishes an advisory, researchers or threat actors develop a proof-of-concept within days, and mass exploitation begins before the patching cycle in most organisations has completed. The Fortinet credential theft campaign earlier this month, which compromised 75,000 firewall and VPN devices, followed exactly this trajectory.
Cisco also disclosed a separate medium-severity flaw in Catalyst SD-WAN Manager (CVE-2026-20262, CVSS 6.5) last week that is also under active exploitation. Enterprise security teams running Cisco infrastructure across multiple product lines should treat this week as a critical patching sprint rather than routine maintenance.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.