
CISCO Unified Communications Manager and PTC Windchill have been added to the CISA Known Exploited Vulnerabilities catalog after both flaws were seen under active attack in June 2026, putting enterprise voice video and product lifecycle systems at immediate risk.
The Cisco flaw tracked as CVE-2026-20230 carries a CVSS score of 8.6 and stems from improper input validation in the WebDialer service, allowing unauthenticated attackers to send crafted HTTP requests that can write files to the underlying operating system and achieve root privileges; it affects Unified Communications Manager releases prior to 14SU6 and 15SU5, as detailed in the vendor advisory. The PTC issue identified as CVE-2026-12569 is rated CVSS 9.3 and involves a deserialization vulnerability in Windchill and FlexPLM that enables remote code execution when malicious objects are processed by the affected services.
A separate zero‑day in Cisco Catalyst SD‑WAN Manager, recorded as CVE-2026-20245 with a CVSS of 7.8, has also been exploited in the wild; attackers leveraged default password manipulation and a malicious CSV file upload to gain elevated access to a service provider’s environment, according to analysis published at securityonline.info. While this SD‑WAN flaw is not yet in the KEV catalog, its use in conjunction with the Cisco UC manager bug highlights a chaining risk for network infrastructure.
Exploitation of the UC manager and Windchill bugs was first observed in early June, with public proof‑of‑concept code appearing shortly after, increasing the likelihood of broader abuse; although no specific threat actor has been attributed, the activity prompted CISA to issue Binding Operational Directive 26‑04 and set a remediation deadline of June 28 2026 for federal agencies, as noted in the security affairs report and the associated CISA alert.
The presence of these vulnerabilities in core collaboration and PLM platforms means a successful breach could give adversaries a foothold for lateral movement, data theft or further ransomware deployment across trusted internal networks, underscoring the need for rapid patching and vigilant monitoring.
Defenders should immediately apply the patches released by Cisco for Unified Communications Manager versions 14SU6 and 15SU5 and for Catalyst SD‑WAN Manager, disable the WebDialer service if it is not required, and restrict exposure of the affected interfaces to trusted network zones; administrators are also advised to review authentication logs for anomalous POST or GET requests that contain unusual payloads and to enforce network segmentation between voice, video and data planes.
For PTC Windchill and FlexPLM, organizations must upgrade to the vendor‑provided fixed releases, audit deserialization endpoints for exposure to untrusted input, enforce strict allow‑lists for incoming SOAP or REST calls, and look for Indicators of Compromise such as unexpected file creation in temporary directories or the appearance of new privileged accounts; staying current with CISA’s KEV entries and following the mitigations outlined in the KEV catalog will help prioritize these actions.