Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
2026-06-04T19:24:23Z•1f12102b229adf36ca916345c998f50728cdb6d180a63f9682ae7f6d63e20f88
AndroidAnthropicCVE-2025-48595CVE-2026-20230CVE-2026-23479CVE-2026-33829CVE-2026-45247CiscoClaude CodeFlutterShellGitHub ActionKEVMagentoRedisSSRFTA4922Unified Communications ManagerWindowsexploit-publicmalvertisingpatchprivilege-escalationproof-of-conceptsupply-chainunauthenticated-attack
What happened
Multiple high-impact vulnerabilities and active campaigns were reported. Cisco patched CVE-2026-20230 in Unified Communications Manager — an unauthenticated SSRF that can write files and be leveraged to escalate to root — and proof-of-concept exploit code is already public. Other notable items include an Anthropic Claude Code GitHub Action flaw that could allow repository takeover, Redis RCE (CVE-2026-23479) discovered by an autonomous tool, Magento deserialization RCE (CVE-2026-45247) added to CISA's KEV catalog, and references to additional exploited or high-risk issues (Windows search URI,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 1f12102b229adf36ca916345c998f50728cdb6d180a63f9682ae7f6d63e20f88
- Enrichment time
- 2026-06-04T19:24:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.