Cisco confirms active exploitation of Unified CM vulnerability in the wild
Source headline: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
Intelligence Summary
Cisco says a Unified CM vulnerability is being exploited in the wild. Early exploitation attempts were observed shortly after the issue was publicly disclosed. A proof-of-concept was available since the disclosure, which may have helped accelerate attacks. The activity indicates real-world risk beyond proof-of-concept testing. Organizations running vulnerable Unified CM deployments should verify exposure and apply Cisco mitigations or updates immediately. Network and device teams should also monitor for related exploitation indicators.
Recommended Action
Inventory where Unified Communications Manager (Unified CM) runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.