A high-severity SSRF vulnerability in Cisco Unified CM, CVE-2026-20230, is now being actively exploited in attacks originating from a single IP address. The flaw, which can lead to root privileges via arbitrary file writes, received full technical disclosure after Defused's weekend observations.

Successful exploitation could let an attacker write files to the underlying operating system that could later be used to elevate to root privileges.
On honeypots, the observed proof-of-concept attempts to write a text file named '/tmp/cve-2026-20230-test.txt'.
Security teams running Cisco Unified CM should apply the June 3 patches immediately and monitor for attempts to write files under /tmp as reconnaissance for follow-on root exploitation.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Xsolis disclosed that a January 2026 phishing attack exposed names, SSNs, medical records and other sensitive data for exactly 1,396,519 individuals. The healthcare AI firm used by over 600 hospitals has notified victims, offered credit monitoring, and strengthened its security controls.
Apple’s System Status page reports performance problems with App Store Connect that began at 9:00 a.m. ET and are affecting some users. The outage has been independently confirmed by multiple developers on X who report errors while managing their apps.
Virgin Media O2 will begin switching off its 2G network in summer 2029, joining BT/EE and Vodafone in a government-coordinated UK phase-out. The move affects not only legacy phones but also smart meters, telecare alarms and other IoT devices that still rely on the 32-year-old technology.