U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog


U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
June 26, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities (KEV) catalog.

The two flaws added to the catalog are:

  • CVE-2026-12569 (CVSS score of 9.3) PTC Windchill and FlexPLM Improper Input Validation Vulnerability
  • CVE-2026-20230 (CVSS score of 8.6) Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

CVE-2026-12569 is a critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM. An attacker can exploit this vulnerability through the deserialization of untrusted data. The flaw impacts all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030.

CVE-2026-20230 is a critical vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM SME that allows an unauthenticated remote attacker to perform server-side request forgery (SSRF) by sending specially crafted HTTP requests to an affected device.

The issue is caused by improper input validation in specific HTTP request handling. If exploited, it can allow the attacker to interact with internal services and, in some cases, write files to the underlying operating system. Those files could later be leveraged to escalate privileges up to root.

A key condition is that the WebDialer service must be enabled for exploitation, and it is disabled by default. However, if active, the impact is severe because it can lead from SSRF to full system compromise.

Cisco warns that public PoC code is available and that successful exploitation could allow attackers to write files that may later be used to gain root privileges, even though it requires a specific service configuration to be exploitable.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to urgently fix the vulnerabilities by June 28, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Summer is kicking in with full force, and with the temperature rising, Netflix’s summer slate of releases, too, picks up heat. It’s time for your watch list to get a new look, whether you’re looking forward to a cozy romance watch or an addictive new series.

Between long-awaited returning series, nostalgic movie additions, true-crime documentaries, and originals that are sure to stun, there’s a little bit of everything arriving on Netflix. The second season of the highly awaited live-action series, Avatar: The Last Airbender, returns at the end of the month.

Other titles coming this month include The Witness (a true-crime show), Office Romance (a rom-com starring Jennifer Lopez), and I Will Find You (another Harlan Coben thriller).

Plus, licensed additions like Poor Things and Little Miss Sunshine will be available to stream from the beginning of the month. Here’s the Netflix schedule for June.

Everything coming to Netflix in June 2026

Your watchlist gets a summer refresh

Arrival Date

Title

June 1

Bee Movie

Creed I-III

Father of the Bride: Part I & II

Friday Night Lights

Fried Green Tomatoes

Hawaii Five-0: Seasons 1-5

Inside Man 1 & 2

Little Miss Sunshine

Miracle

Muriel’s Wedding

My Best Friend’s Wedding

Rocky 1-5

Rudy

Runaway Bride

Scooby-Doo 1 & 2

The Big Lebowski

The Karate Kid Part I-III

The Wedding Planner

June 4

The Murder of Rachel Nickell

The Witness

June 5

Office Romance

June 6

Grey’s Anatomy: Season 22

Resident Alien: Season 4

June 7

Poor Things

June 8

Shrill: Seasons 1-3

June 10

Outlast: The Jungle

The Rest is Football

June 11

Sweet Magnolias: Season 5

June 12

Maternal Instinct

June 13

Song Sung Blue

June 15

Percy Jackson 1 & 2

June 16

America’s Sweethearts: Dallas Cowboys Cheerleaders: Season 3

Beavis and Butt-Head: The Mike Judge Collection Vol. 1-3

Mike Judge’s Beavis and Butt-Head: Seasons 1-2

June 18

I Will Find You

June 19

Color Book

Voicemails for Isabelle

June 24

The American Experiment

In the Hand of Dante

June 25

Avatar: The Last Airbender: Season 2

June 26

Chris & Martina: The Final Set

Little Brother

June 30

Sullivan’s Crossing: Season 4


If you’re on the lookout for new Netflix titles, make sure you enable desktop or mobile app notifications. You can also browse the “New and Popular” tab regularly to refresh your watchlist with new titles.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four

Stream licensed and original programming with a monthly Netflix subscription.




Source link