Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.
The flaw is a server-side reques...
Get updates from The Hacker News | #1 Trusted Source for Cybersecurity News via email, on your phone or read them on follow.it on your own custom news page.
You can filter the news from The Hacker News | #1 Trusted Source for Cybersecurity News that get delivered to you using tags or topics or you can opt for all of them. Unsubscription is also very simple.
See the latest news from The Hacker News | #1 Trusted Source for Cybersecurity News below.
Site title: The Hacker News | #1 Trusted Source for Cybersecurity News