Cisco Unified CM SSRF flaw exploited in wild attacks
A server-side request forgery vulnerability (CVE-2026-20230) in Cisco Unified CM and Unified CM SME is under active exploitation, allowing unauthenticated attackers to write files and escalate privileges to root. Cisco released patches on June 3, but reconnaissance activity has since been detected.