Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

2026-06-05T01:24:36Z607a1d540bcbf258da7987c256080ba2b33e87aaa9ce640cdf212f4eee0d9a8b
AnthropicCISACiscoDesckVB RATFlutterShellGoogle GeminiKEVMagentoRCERedisSSRFTA4922deserializationexploitgithub-actionsmacOS-malwaremalspammalvertisingoauth-token-theftphishingproof-of-conceptsupply-chainvulnerability

What happened

Multiple high-impact security incidents and disclosures: Cisco patched CVE-2026-20230 — an SSRF in Unified Communications Manager that allows unauthenticated file write and local privilege escalation to root, with public PoC available. Researchers disclosed additional critical flaws and active exploitings including Redis RCE (CVE-2026-23479) found by an autonomous AI tool and a deserialization-based Magento extension RCE (CVE-2026-45247, CVSS 9.8) added to CISA's KEV list. Other notable issues include a supply-chain/superuser risk in Anthropic's Claude Code GitHub Action that allowed repo take

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
607a1d540bcbf258da7987c256080ba2b33e87aaa9ce640cdf212f4eee0d9a8b
Enrichment time
2026-06-05T01:24:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public · Baitaphish