Attackers exploit Cisco phone system flaw, plant webshells
Starting the weekend of June 21, 2026, attackers began scanning and then breaking into Cisco Unified Communications Manager phone systems that had the WebDialer feature turned on, using a bug that needed no password. By June 24 researchers confirmed automated attacks were installing hidden webshells that let attackers keep access even after the system is patched. Cisco and CISA both confirmed real-world exploitation and pushed for urgent patching.
- Started
- Jun 21, 2026
- Latest activity
- Jul 2, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- Worldwide, United States
- Sectors
- Telecom, Technology, Multiple sectors, Government
- Scale
- unknown number of organizations running exposed Cisco Unified CM systems with the WebDialer feature enabled
Current status
As of July 2, 2026 Cisco confirmed attackers were exploiting the flaw, with the first exploitation attempts observed the prior week; no report since has said the activity stopped.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Impact
Attackers could write files to vulnerable Cisco Unified CM servers without logging in, and researchers confirmed some servers had multi-stage webshells installed that give attackers a way back in even after the original bug is fixed.
What to do
If your organization runs Cisco Unified CM with WebDialer enabled, apply Cisco's patch right away and check the system for signs of a webshell, since patching alone will not remove one that is already there.
Timeline
-
Aug 2, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 2, 2026
SecurityWeek reported Cisco confirmed in-the-wild exploitation was continuing, with attack attempts observed through late June.
Activesecurityweek.com -
Jul 2, 2026
Cisco confirmed in-the-wild exploitation of the vulnerability, saying the first exploitation attempts were observed the prior week.
Activesecurityweek.com -
Jun 26, 2026
CISA ordered US federal civilian agencies to patch the flaw by June 29 after adding it to its Known Exploited Vulnerabilities catalog.
Activebleepingcomputer.com -
Jun 26, 2026
CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until June 28 to patch.
Activebleepingcomputer.com -
Jun 24, 2026
Threat intelligence firm Defused confirmed automated, Tor-routed scans were installing webshells on vulnerable systems with WebDialer enabled.
Activetechtimes.com -
Jun 24, 2026
Threat intelligence firm Defused confirmed automated Tor-routed sweeps were installing multi-stage webshells on vulnerable Unified CM servers.
Activetechtimes.com -
Jun 23, 2026
Researchers confirmed CVE-2026-20230, a critical SSRF flaw in Cisco Unified Communications Manager, was being actively exploited in attacks.
Emergingbleepingcomputer.com -
Jun 21, 2026
Reconnaissance probes against internet-facing Cisco Unified CM WebDialer endpoints were first observed over the weekend of June 21 to 22.
Emergingtechtimes.com
Sources
- CISA warns of exploited Cisco call server flaw BleepingComputer Jun 26, 2026
- Cisco Call Manager zero-day lets attackers crash calls SecurityWeek Jul 2, 2026
- Cisco finally confirms attackers exploiting Unified CM flaw BleepingComputer Jul 2, 2026
- Cisco Unified CM CVE-2026-20230: Webshell Drops Confirmed Tech Times Jun 24, 2026
- In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw Dark Reading Jun 25, 2026
- Cisco security advisory (AV26-547), Update 1 NVD/CISA KEV Jun 22, 2026
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks BleepingComputer Jun 23, 2026
- Attackers exploit Cisco Unified CM flaw weeks after patch release CSO Online Jun 24, 2026
Related reports
- LegacyHive Windows flaw can hijack admin accounts Jul 17, 2026
- Windows zero-day lets attackers crash or hijack apps Jul 16, 2026
- MantisBT bug can let attackers hijack admin accounts Jul 15, 2026
- MantisBT flaw lets a rogue admin steal all data Jul 15, 2026
- MantisBT admin flaw lets admins run server code Jul 15, 2026
- MantisBT setup page bug enables admin credential phishing Jul 15, 2026
- MantisBT install page flaw enables admin phishing Jul 15, 2026
- Windows Defender zero-day lets attackers bypass protections Jul 9, 2026
- Windows zero-day lets attackers hijack user accounts Jul 9, 2026
- Cisco Call Manager zero-day lets attackers crash calls Jul 2, 2026
- Windows 0-day lets normal users access other users' settings Jun 29, 2026
- Windows LegacyHive flaw lets users tamper with admin accounts Jun 29, 2026