A critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-20230, CVSS 8.6 HIGH) in Cisco Unified Communications Manager is being actively exploited via automated Tor-based attacks to deploy webshells and achieve remote code execution. The attack chain abuses the WebDialer SSRF to deploy a rogue Apache Axis service as a first-stage payload. The article does not provide specific affected or fixed version information.
CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all via Tor,” threat intelligence firm Defused warned today, after observing initial attacks over the weekend. “The observed chain abuses the WebDialer SSRF to deploy a rogue Apache Axis service, uses that service to write a first-stage … More → The post Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) appeared first on Help Net Security .