What We Know
REST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gapsREST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gaps
Older than 2 weeksJust now

Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Older than 2 weeks

What We Know

Security researchers and multiple security news sites report that CVE-2026-20230, a high‑severity server‑side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (Unified CM/CUCM), is being actively exploited in the wild. Reports say the flaw can be triggered by unauthenticated HTTP requests to cause SSRF, perform arbitrary file writes, and enable attackers to drop webshells on vulnerable appliances. Several outlets note attacks began weeks after a patch was released.

Technical disclosure teams and independent researchers published detailed writeups and demonstrations of the full exploit chain. According to the reporting, attackers have used the vulnerability to write files that lead to remote code execution and, in at least theoretical demonstrations, could escalate to root‑level access. The activity was described both as active exploitation in the wild and as a same‑day/full‑chain RCE sweep in technical analysis, and vendors and security sites have urged affected customers to address the issue.

Source Comparison

Aligned reporting
8 corroborates - 0 adds context - 0 conflicts

Corroborates