Critical Cisco Unified CM Bug Patched as Public Exploit Code Emerges

2026-06-04T14:51:46Zb8459d9b635c9928254207da1ee823fb2413976ff3172559d0dff85aa7f833cb
AI support abuseAndroid patchCISA KEVCVE-2025-48595CVE-2026-0826CVE-2026-20230Cisco Unified CMGamaredonHP PolyInstagram account hijackLinux kernelOperation KRATOSOutlook espionageSSRFTelegram C2VS Code exploitVisual Studio Code zero-dayVoIP phonesWinRARactively exploitedemail exfiltrationfileless malwareillegal streaming takedownpublic PoCunauthenticated RCE

What happened

This feed contains multiple high-impact security developments: Cisco patched a critical unauthenticated SSRF in Unified CM (CVE-2026-20230) and public proof‑of‑concept exploit code is circulating; Gamaredon actors are exploiting a WinRAR vulnerability to deliver modular, nearly fileless backdoors to Ukrainian targets (C2 resolution via Telegram); a researcher publicly released a new Visual Studio Code zero‑day exploit; Rapid7 disclosed a critical unauthenticated stack overflow in HP Poly VoIP phones leading to root RCE (CVE-2026-0826) with available patches; Google’s June Android updates fix 1

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b8459d9b635c9928254207da1ee823fb2413976ff3172559d0dff85aa7f833cb
Enrichment time
2026-06-04T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.