Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.
The flaw is a server-side reques...
Follow The Hacker News's news and updates in a matter of seconds! We will deliver any update via email, phone or you can read them from here on the site on your own news page.
You can even combine different feeds with the feed for The Hacker News.
Subscribing and unsubscribing is fast, easy and risk free.
The whole service is free of cost.
The Hacker News: The Hacker News | #1 Trusted Cybersecurity News Site