THREAT OPS › Threat News › Silent;Call — Pre-Authentication Remote Root in Cisco CUCM 15.x (SKYLINE-2026-001/002/003)
Silent;Call — Pre-Authentication Remote Root in Cisco CUCM 15.x (SKYLINE-2026-001/002/003)
<p>Posted by 0xReadingSteiner via Fulldisclosure on Aug 06</p>## Advisory Information<br /> <br /> - Advisory IDs: SKYLINE-2026-001, SKYLINE-2026-002, SKYLINE-2026-003<br /> - Title: Pre-Authentication Remote Root via Tomcat Manager Header Injection + Hardcoded Credentials<br /> - CVSSv3.1: 10.0 (Critical) — AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H<br /> - CWE: CWE-798, CWE-644, CWE-269<br /> - Product
MITRE ATT&CK techniques
- CredentialsT1589.001
Original source: https://seclists.org/fulldisclosure/2026/Aug/0