Skip to content

SSRF Vulnerability in Cisco Unified CM Actively Exploited

Bottom line: An SSRF vulnerability in Cisco Unified CM is being actively exploited in practice and potentially enables root access, making rapid patching or disabling vulnerable services essential.

A Server-Side-Request-Forgery (SSRF) vulnerability in Cisco Unified Communications Manager is currently being exploited in active attacks. The flaw potentially enables root access to affected systems.

The SSRF vulnerability in Cisco Unified CM allows attackers to access backend systems through manipulated requests and abuse internal resources. In active attack scenarios, this is being leveraged to escalate to root privileges.

For CISOs, this represents an immediate threat to communications infrastructure. Unified Communications Manager is often a central system in enterprise environments and presents an attractive target for attackers seeking to gain control over company-wide telephony and messaging systems.

Immediate action is required: patching affected systems once an official security patch from Cisco becomes available, temporarily disabling vulnerable functions if a patch is not yet available, and monitoring access logs for suspicious request patterns. Network segmentation of affected systems reduces the risk of spread in case of successful access.


Source: www.security-insider.de · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: