
CVE-2026-20230: Cisco Unified CM — Webshell RCE in Active Exploitation (June 2026)
CVE-2026-20230 — Cisco Unified Communications Manager
CVE-2026-20230 is a critical server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM) that enables attackers to achieve remote code execution by dropping webshells. The flaw is under active exploitation as of June 2026, with automated attacks observed leveraging Tor to deliver malicious payloads. Severity is critical; immediate remediation is required.
Attack Vector
Attackers exploit the SSRF flaw in Unified CM to bypass network restrictions and write arbitrary files to the underlying operating system. Automated sweeps originating from Tor exit nodes have been detected, with payloads designed to drop webshells and escalate privileges. Once a webshell is established, adversaries gain remote code execution and file write capabilities, often leading to root-level access. No user interaction is required; exposure of the Unified CM interface is sufficient for compromise.
Who Is at Risk
All organizations running Cisco Unified Communications Manager are at risk, regardless of deployment size or region. The campaign is global and targets internet-exposed Unified CM instances. No specific versions have been excluded; all supported and unpatched versions should be considered vulnerable. Organizations confirmed affected include those monitored by Defused threat intelligence.
Patch & Mitigate
- Patch: Apply the latest Cisco security update for Unified CM addressing CVE-2026-20230 immediately. Refer to Cisco’s official advisory for version specifics.
- Workaround: If patching is not immediately possible, restrict external access to Unified CM interfaces and monitor for unusual file writes.
- Detect: Review server logs for unexpected file creation, especially in web-accessible directories. Monitor for inbound requests from Tor exit nodes and look for webshell indicators such as suspicious POST requests or new executable files.
MITRE ATT&CK
- TA0007 — Discovery: Attackers enumerate system and network information post-compromise.
- TA0009 — Collection: Webshells enable adversaries to collect sensitive data and credentials from Unified CM servers.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

