Cisco released patches for CVE-2026-20230, a critical SSRF vulnerability in Unified CM that allows unauthenticated remote attackers to write files and potentially escalate to root privileges. Infrastructure teams managing Cisco telephony systems need to upgrade immediately or disable the WebDialer service, which is required for exploitation but disabled by default. Public exploit code is available and while no active attacks have been reported, the availability of PoC code makes rapid patching critical.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





