Federal Agency Demands Immediate Patch for Actively Exploited Cisco Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a actively exploited vulnerability in Cisco's Unified Communications Manager Server by this Sunday. The flaw, tracked as CVE-2026-20230, is a server-side request forgery (SSRF) vulnerability that has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Under Binding Operational Directive (BOD) 26-04, agencies have until June 28 to apply the necessary fix. Cisco rated the vulnerability as critical severity and issued a patch on June 3, cautioning that attackers could exploit it remotely and without any credentials through specially crafted HTTP requests. At the time of disclosure, a proof-of-concept exploit was already publicly available, though Cisco had not yet seen it used in real-world attacks. That changed last weekend, when threat detection firm Defused spotted the vulnerability being actively weaponized to write arbitrary text files onto affected systems. The identity and nature of the threat actors behind these attacks remain unknown.

A Second Critical Flaw Hits Manufacturing Software

CISA has also flagged CVE-2026-12569, adding it to the KEV catalog alongside the Cisco vulnerability. This flaw affects PTC's Windchill and FlexPLM platforms — product lifecycle management (PLM) tools widely used across manufacturing, engineering, retail, footwear, apparel, and consumer goods industries. CVE-2026-12569 is a critical remote code execution (RCE) vulnerability stemming from insecure deserialization of untrusted data, meaning attackers could potentially take full control of affected systems. PTC disclosed the issue on June 18 and published a security advisory directing customers to a full list of impacted versions and urging immediate action. The flaw impacts all versions up to 11.0, as well as select releases across the 11.1, 11.2, 12.0, 12.1, and 13.0 branches. Federal agencies face the same June 28 deadline to remediate this vulnerability.

Source 🔗:https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/