securityonline.info 6/26/2026, 3:31:31 AM · external

Cisco and PTC flaws under active attack, CISA adds to KEV list

Cisco and PTC flaws under active attack, CISA adds to KEV list
Developing story vulnerability 13 articles tracked
Cisco Unified CM and PTC Windchill vulnerabilities exploited, added to CISA KEV
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE page discusses two critical vulnerabilities that have been added to the CISA KEV Catalog on June 25, 2026. These vulnerabilities are affecting Cisco Unified Communications Manager and PTC Windchill, both of which are reportedly being actively exploited. The Cisco issue (CVE-2026-20230) is a Server-Side Request Forgery (SSRF) flaw that allows unauthorized access to the system, whereas the PTC issue (CVE-2026-12569) permits remote code execution through a deserialization vulnerability.

Both products are integral to enterprise networks, necessitating immediate updates to mitigate the risks. Users are urged to upgrade their systems before the CISA-set remediation deadline of June 28, 2026.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline