• News/
  • bleepingcomputer-20260626194306

CISA sets urgent deadline to fix Cisco flaw exploited in attacks

BleepingComputer
·
Bill Toulas
·
Published Jun 26, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. Identified as CVE-2026-20230, the security issue is server-side request forgery (SSRF) and has been added to the agency's catalog of Known Exploited Vulnerabilities (KEV). Per Binding Operational Directive (BOD) 26-04, the remediation is deemed urgent and must addressed by Sunday, June 28. Cisco marked CVE-2026-20230 with critical severity and released a patch on June 3, warning that it could be exploited remotely and without authentication via specially crafted HTTP requests. At the time, the company noted that a proof-of-concept exploit existed, but had found no evidence of active exploitation. Last weekend, threat detection startup Defused observed the vulnerability being exploited in attacks to write arbitrary text files to affected endpoints. It is currently unknown what type of threat actor is leveraging CVE-2026-20230 in attacks. CISA has also added CVE-2026-12569 to the KEV catalog, an improper input validation flaw impacting the PTC Windchill and FlexPLM software products. Both are product lifecycle management (PLM) systems developed by PTC specifically for the manufacturing, engineering, retail, footwear, apparel, and consumer products industries. CVE-2026-12569 is a critical-severity remote code execution (RCE) vulnerability that can be exploited through th...

Read full article

Affected Software

3 affected components
Cisco Unified Communications Manager Server=CVE-2026-20230
PTC Windchill<=11.0, =11.1, =11.2, =12.0, =12.1, =13.0
PTC FlexPLM<=11.0, =11.1, =11.2, =12.0, =12.1, =13.0

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses an urgent deadline set by CISA for federal agencies to patch a Cisco flaw due to ongoing exploitation.

2

What vulnerability is addressed in the article?

The vulnerability addressed is CVE-2026-20230, a server-side request forgery (SSRF) issue in Cisco Unified Communications Manager Server.

3

What is the deadline for federal agencies to fix the vulnerability?

Federal agencies have until Sunday to implement the necessary patch for the Cisco vulnerability.

4

What software products are affected by this vulnerability?

The affected software products include Cisco Unified Communications Manager Server, PTC Windchill, and PTC FlexPLM.

5

What are the implications of this vulnerability being actively exploited?

The active exploitation of this vulnerability poses significant risks to the security of federal agency communication systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203