Cisco Unified CM Flaw (CVE-2026-20230) Actively Exploited for Webshell Deployment and Root Access

web banner with online information on computer

A critical vulnerability affecting Cisco’s Unified Communications Manager (Unified CM) is currently being exploited by malicious actors, according to multiple security vendors and threat intelligence firms. The vulnerability, tracked as CVE-2026-20230, is a server-side request forgery (SSRF) flaw that allows unauthenticated attackers to write arbitrary files to the underlying operating system. This capability presents a significant risk, potentially enabling attackers to elevate their privileges to root level on compromised systems.

The exploitation chain involves deploying a rogue Apache Axis service, writing a first-stage JSP file-writer, and dropping a second-stage command-execution shell. Successful exploitation requires the WebDialer service to be enabled; however, it’s typically disabled by default in most deployments.

Threat intelligence firm Defused reported observing the first confirmed exploitation of CVE-2026-20230 over the weekend following June 3, 2026. The vulnerability stems from improper input validation for specific HTTP requests, allowing attackers to trigger it by sending a specially crafted request. The ability to write files to the underlying operating system opens the door to more advanced attacks, including persistent access and further compromise of the network infrastructure.

Cisco addressed this vulnerability by releasing security updates on June 3, 2026. These updates are crucial for mitigating the risk of exploitation. However, reports indicate that attackers have been actively exploiting the flaw in the weeks following the patch release. Automated Tor-routed sweeps were observed installing webshells on vulnerable systems as early as June 24, highlighting the speed and efficiency with which attackers are leveraging publicly available information to target exposed infrastructure.

Organizations utilizing Cisco Unified Communications Manager should prioritize applying the security updates released by Cisco. While WebDialer is disabled by default, administrators should verify its status and disable it if not actively required. Monitoring network traffic for suspicious activity related to Apache Axis or Tomcat services can also help detect potential exploitation attempts. The technical details of this vulnerability include the use of a first-stage JSP file writer and a second-stage command execution shell; understanding these components is vital for effective incident response and forensic analysis.

Sources: