Security · 2h ago
Cisco Unified CM Flaw Exploited After PoC Shows File-Write to Root
Attackers are exploiting CVE-2026-20230, a critical 8.6-severity flaw in Cisco Unified CM and Unified CM SME, after a proof-of-concept demonstrated a file-write path to root access. The vulnerability stems from improper input validation in HTTP requests, allowing unauthenticated remote exploitation. Cisco has not yet released a patch, leaving systems exposed.
Meridian48 take
The rapid exploitation following PoC publication underscores the danger of full-disclosure timelines when vendors lag on patches.
Read the full reporting
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root →
The Hacker News
cisco-unified-cmcve-2026-20230