Cisco News Articles

Recent news articles refferecing the vendors vulnerabilities.

Cisco finally confirms attackers exploiting Unified CM flaw

Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June.

3 weeks ago

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

Cisco confirmed that hackers are exploiting CVE-2026-20230, a Unified CM vulnerability allowing privilege escalation to root.

3 weeks ago

Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look

3 weeks ago

CISA Orders Immediate Patch for Actively Exploited Cisco Unified CM SSRF Flaw - IT Security News

  CISA has moved quickly against a serious Cisco vulnerability because the issue is already being exploited and could expose government and enterprise communications systems to deeper compromise. The flaw, CVE-2026-20230, affects Cisco Unified Communications Manager and Cisco Unified CM…Read more →

3 weeks ago

CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited.

4 weeks ago

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Ravie LakshmananJun 24, 2026Vulnerability / Network Security

4 weeks ago

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments.

4 weeks ago

Cisco Unified CM SSRF Flaw Exploited in the Wild

CVE-2026-20230, a Cisco Unified CM SSRF bug, is being used to drop webshells via Tor. Check WebDialer status and patch to 14SU6 immediately.

4 weeks ago

The hits keep on coming for Cisco vulnerabilities

CVE-2026-20230 under exploitation, while an earlier SD-WAN 0-day looks even worse than we thought

4 weeks ago

The hits keep on coming for Cisco vulnerabilities

CVE-2026-20230 under exploitation, while an earlier SD-WAN 0-day looks even worse than we thought

4 weeks ago

Cisco SD-WAN Root Access: Mandiant Exposes Eight-Month Stealth Attack Chain

Cisco SD-WAN zero-day exploit CVE-2026-20245 was active for eight months before disclosure, Mandiant reveals in a new post-mortem. Attackers uploaded a crafted CSV file to inject a root account via

4 weeks ago

Cisco SD-WAN Zero-Day Exploit: Mandiant Reveals Malicious CSV Opened Root Shell

Cisco SD-WAN zero-day CVE-2026-20245 was exploited months before disclosure: Mandiant reveals how a malicious CSV file injected a rogue root account into Linux passwd files, giving attackers full

4 weeks ago

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

Mandiant says CVE-2026-20245 was exploited as a Cisco SD-WAN zero-day to escalate admin access to root on a provider network.

4 weeks ago

Cisco SD-WAN Zero-Day Exploited Months Before Patching

Mandiant details exploitation of CVE-2026-20245, a Cisco Catalyst SD-WAN vulnerability exploited as a zero-day months prior to disclosure.

4 weeks ago

Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices.

4 weeks ago

Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure

Researchers believe rogue peering was used to connect to the victim's SD-WAN devices to gain admin privileges and root-level access.

4 weeks ago

Cisco Unified CM CVE-2026-20230: Webshell Drops Confirmed, Patch Alone Won't Evict Attackers

Cisco Unified CM vulnerability CVE-2026-20230 has escalated from weekend reconnaissance to automated Tor-routed webshell drops as of June 24, 2026. Attackers are deploying three-stage JSP command

4 weeks ago

Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level Access - IT Security News

A sophisticated threat actor is actively targeting SD-WAN infrastructure at a major service provider. The campaign culminated in the exploitation of a zero-day privilege escalation vulnerability, now tracked as CVE-2026-20245 (CVSS 7.8), in Cisco Catalyst SD-WAN Manager, enabling attackers to…Read m...

4 weeks ago

Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level Access

A sophisticated threat actor is actively targeting SD-WAN infrastructure at a major service provider. The campaign culminated in the exploitation of a zero-day privilege escalation vulnerability, now tracked as CVE-2026-20245 (CVSS 7.8), in Cisco Catalyst SD-WAN Manager, enabling attackers to silent...

4 weeks ago

Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild - IT Security News

Attackers exploit Cisco Unified CM flaw (CVE-2026-20230) allowing unauth HTTP requests to trigger SSRF, write files, and gain root access Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting.…Read more ...

1 month ago

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) - IT Security News

CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells,...

1 month ago

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) - Help Net Security

CVE-2026-20230, a SSRF vulnerability affecting Cisco's Unified Communications Manager (Unified CM), is being exploited to drop webshells.

1 month ago

Critical Cisco Unified CM and SME Flaw Enables Remote Attacker to Launch SSRF Attacks

Cisco disclosed a SSRF flaw in Unified CM and Unified CM SME that could let unauthenticated attackers write files and gain root access.

1 month ago

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

Cisco Unified CM CVE-2026-20230 is under active exploitation, allowing file writes on WebDialer-enabled systems.

1 month ago

Hackers Exploiting Cisco Unified CM Vulnerability

CVE-2026-20230, a recently patched vulnerability affecting Cisco’s Unified Communications Manager, is being exploited in attacks.

1 month ago

No more news articles to load.