Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
2026-06-05T01:24:36Z•607a1d540bcbf258da7987c256080ba2b33e87aaa9ce640cdf212f4eee0d9a8b
AnthropicCISACiscoDesckVB RATFlutterShellGoogle GeminiKEVMagentoRCERedisSSRFTA4922deserializationexploitgithub-actionsmacOS-malwaremalspammalvertisingoauth-token-theftphishingproof-of-conceptsupply-chainvulnerability
What happened
Multiple high-impact security incidents and disclosures: Cisco patched CVE-2026-20230 — an SSRF in Unified Communications Manager that allows unauthenticated file write and local privilege escalation to root, with public PoC available. Researchers disclosed additional critical flaws and active exploitings including Redis RCE (CVE-2026-23479) found by an autonomous AI tool and a deserialization-based Magento extension RCE (CVE-2026-45247, CVSS 9.8) added to CISA's KEV list. Other notable issues include a supply-chain/superuser risk in Anthropic's Claude Code GitHub Action that allowed repo take
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 607a1d540bcbf258da7987c256080ba2b33e87aaa9ce640cdf212f4eee0d9a8b
- Enrichment time
- 2026-06-05T01:24:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.