CVE-2026-20230: Cisco Unified CM flaw leveraged for unauthenticated file writes
Source headline: Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Intelligence Summary
Attackers have started exploiting a Cisco Unified CM vulnerability after a proof-of-concept demonstrated a file-write path to the root user. The issue affects Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME). The flaw is caused by improper input validation in response to crafted HTTP requests. Because exploitation is reported as unauthenticated and remote, affected systems are at heightened risk of compromise. Organizations running these products should review Cisco guidance, apply available patches, and restrict exposure to untrusted networks.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.