Protect.Computer
NEWS

Cisco Phone System Flaw Being Exploited — Patch Before June 28

· 1 min read · Network safety Device safety
Cisco Phone System Flaw Being Exploited — Patch Before June 28

A serious security flaw has been found in Cisco Unified Communications Manager (Unified CM), the system many businesses use to run their internal phone networks. Tracked as CVE-2026-20230, the flaw is a type of vulnerability called Server-Side Request Forgery (SSRF) that lets an attacker send specially crafted web requests to the system — and write arbitrary files to the underlying server with no login required. Security researchers observed attackers actively exploiting this weakness in the wild, planting files that could later be used to gain full root-level control of the phone system. Cisco released a patch on June 3, and CISA has ordered all U.S. federal agencies to apply it by Sunday, June 28.

If your employer uses Cisco phone systems — for desk phones, call centres, or a company-wide softphone app — this is relevant to you indirectly. A compromised phone server could be used to intercept internal calls, record voicemail, or as a launching pad for deeper attacks inside the corporate network. The fix is available; the only remaining action is for your IT team to apply it before the deadline.

How to check if you’re affected

Affected versions include Cisco Unified CM and Unified CM SME running any release older than 14SU6 or 15SU5. If your workplace runs Cisco phone systems:

  1. Forward this article to your IT or security team and ask them to confirm the patched version is deployed.
  2. Ask whether the WebDialer service is enabled — successful exploitation requires WebDialer to be active. If it is enabled on an unpatched system, escalate urgently: the patch deadline is June 28.

Home users and small businesses not running Cisco Unified CM are not directly affected by this specific flaw.

Sources

Related reading