Last Updated: June 26, 2026 4:28 PM
What’s Happening
CVSSv3: 8.6
Initially published by Cisco on June 3rd, 2026 this vulnerability has been found EITW. A patch is available. It has no workarounds. This vulnerability requires WebDialer to be enabled (disabled by default). Cisco is treating it as a critical vulnerability because it allows for root privilege escalation. A POC was made publicly available on Github as of June 4th, 2026.
Cisco’s Advisory:
Actions
Update to the latest version of Cisco Unified CM SME. Disable WebDialer if it’s not needed.
Notes
https://www.cve.org/CVERecord?id=CVE-2026-20230
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34137
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230
https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/