Dormant High impact Data breach Checked 1w ago

Attackers exploit Cisco phone system flaw, plant webshells

Starting the weekend of June 21, 2026, attackers began scanning and then breaking into Cisco Unified Communications Manager phone systems that had the WebDialer feature turned on, using a bug that needed no password. By June 24 researchers confirmed automated attacks were installing hidden webshells that let attackers keep access even after the system is patched. Cisco and CISA both confirmed real-world exploitation and pushed for urgent patching.

Started
Jun 21, 2026
Latest activity
Jul 2, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
Worldwide, United States
Sectors
Telecom, Technology, Multiple sectors, Government
Scale
unknown number of organizations running exposed Cisco Unified CM systems with the WebDialer feature enabled

Current status

As of July 2, 2026 Cisco confirmed attackers were exploiting the flaw, with the first exploitation attempts observed the prior week; no report since has said the activity stopped.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Impact

Attackers could write files to vulnerable Cisco Unified CM servers without logging in, and researchers confirmed some servers had multi-stage webshells installed that give attackers a way back in even after the original bug is fixed.

What to do

If your organization runs Cisco Unified CM with WebDialer enabled, apply Cisco's patch right away and check the system for signs of a webshell, since patching alone will not remove one that is already there.

Timeline

  1. Aug 2, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 2, 2026

    SecurityWeek reported Cisco confirmed in-the-wild exploitation was continuing, with attack attempts observed through late June.

    Activesecurityweek.com
  3. Jul 2, 2026

    Cisco confirmed in-the-wild exploitation of the vulnerability, saying the first exploitation attempts were observed the prior week.

    Activesecurityweek.com
  4. Jun 26, 2026

    CISA ordered US federal civilian agencies to patch the flaw by June 29 after adding it to its Known Exploited Vulnerabilities catalog.

    Activebleepingcomputer.com
  5. Jun 26, 2026

    CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until June 28 to patch.

    Activebleepingcomputer.com
  6. Jun 24, 2026

    Threat intelligence firm Defused confirmed automated, Tor-routed scans were installing webshells on vulnerable systems with WebDialer enabled.

    Activetechtimes.com
  7. Jun 24, 2026

    Threat intelligence firm Defused confirmed automated Tor-routed sweeps were installing multi-stage webshells on vulnerable Unified CM servers.

    Activetechtimes.com
  8. Jun 23, 2026

    Researchers confirmed CVE-2026-20230, a critical SSRF flaw in Cisco Unified Communications Manager, was being actively exploited in attacks.

    Emergingbleepingcomputer.com
  9. Jun 21, 2026

    Reconnaissance probes against internet-facing Cisco Unified CM WebDialer endpoints were first observed over the weekend of June 21 to 22.

    Emergingtechtimes.com

Sources

Related reports