CVE-2026-20230: Cisco Unified CM SSRF → Root — Tor-Routed Webshell Drops Confirmed, Patch Now

Technical root cause of the Cisco Unified CM SSRF vulnerability exploited in the wild to drop Tor-routed root webshells.

CVE-2026-20230: Cisco Unified CM SSRF → Root — Tor-Routed Webshell Drops Confirmed, Patch Now

This post is part of the Week of June 26, 2026 Security Roundup.

Vulnerability Overview

CVE-2026-20230 is a Server-Side Request Forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (Unified CM SME). Cisco assigned it CVSS 8.6 and rated it Critical due to the exploitation chain's ability to achieve root-level code execution. Active exploitation with automated Tor-routed webshell drops was confirmed by June 24, 2026.

CVE: CVE-2026-20230 | CVSS: 8.6 High (Critical risk rating) | Vendor Patch: June 3, 2026 | Public PoC Available: June 5, 2026 | Active Exploitation: June 22–24, 2026

Technical Details

The flaw resides in Cisco's WebDialer service — a legacy component of Unified CM that allows browser-initiated click-to-dial functionality. WebDialer performs HTTP requests to internal services based on user-supplied input. Improper validation of specific HTTP request parameters enables an unauthenticated attacker to manipulate these requests to reach arbitrary internal network endpoints or write files to the underlying operating system.

Full Exploitation Chain (3-Stage)

  1. Stage 1 — SSRF to Internal File Write: Attacker sends a crafted HTTP request to the WebDialer service endpoint. The SSRF is used to write a malicious file to an OS path accessible by the CM application server. No authentication is required — the WebDialer service is unauthenticated by default.
  2. Stage 2 — JSP Webshell Deployment: The written file is a three-stage JSP command shell. Stage 1 drops a loader JSP; Stage 2 is fetched from the attacker's C2 and contains the actual command execution payload; Stage 3 establishes persistence and provides an interactive shell interface.
  3. Stage 3 — Root Elevation: The deployed webshell executes within the Unified CM application server context. Attackers then exploit local privilege escalation to reach root, enabling full OS takeover: credential extraction, pivot to adjacent network segments, and lateral movement into the unified communications infrastructure.

As of June 24, attackers are routing exploitation through Tor exit nodes, making IP-based blocking ineffective. The progression from initial PoC to automated Tor-routed campaigns took fewer than 19 days.

Prerequisite: WebDialer Service Must Be Enabled

Exploitation requires that the WebDialer service is enabled (it is enabled by default on most Unified CM installations). Organizations that have disabled WebDialer are not exposed to this specific attack surface, though disabling after exploitation does not evict a dropped webshell.

Affected Versions

Cisco Unified Communications Manager and Unified CM SME prior to the patched releases (June 3, 2026). Refer to Cisco's official advisory for the full version matrix.

Detection

  • Audit Unified CM logs for unexpected HTTP requests to WebDialer service endpoints containing path traversal or SSRF patterns.
  • Search for newly created JSP files in non-standard application directories.
  • Examine process trees for unexpected child processes spawned by the Tomcat/application server process.
  • Monitor for outbound connections from the Unified CM server to Tor exit nodes (UDP/TCP to known Tor relay IPs).
  • If already patched, still audit for prior compromise: patching alone does not evict a dropped webshell.

Remediation

  • Apply Cisco's patch immediately (released June 3, 2026). See the official advisory for affected versions.
  • Disable WebDialer if not operationally required: in Cisco Unified CM Administration, navigate to System → Service Parameters, select the Unified CM server, and disable the WebDialer service. This eliminates the attack surface entirely.
  • Restrict network access to Unified CM management and service interfaces to trusted IP ranges via firewall ACLs.
  • After patching, conduct a compromise assessment: search for unexpected JSP files, review web server access logs for SSRF payloads, and check for unauthorized outbound connections.
  • Harden post-compromise: rotate all Unified CM admin credentials, revoke any API tokens or service accounts with access to the system, and force password resets for any account that may have been harvested from a compromised CM database.

← Back to the Security Roundup: Week of June 26, 2026

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther