SECURITYTHE HACKER NEWS
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a server-side request forgery vulnerability (CVE-2026-20230) in Unified Communications Manager, allowing unauthenticated attackers to write files and escalate to root. Proof-of-concept exploit code is now public, though Cisco's PSIRT reports no observed attacks yet.
Mentioned
Related Signal
Adjacent reporting
- LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
- Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
- Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
- The Internet Is Falling Down- CPanel/WHM Authentication Bypass CVE-2026-41940
- PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation