Urgent Patch Advisory: Active Exploitation of Cisco and PTC Software Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch two critical vulnerabilities in Cisco Unified Communications Manager Server and PTC's Windchill and FlexPLM software by June 28. These vulnerabilities, CVE-2026-20230 and CVE-2026-12569, are being actively exploited, posing significant risks to affected systems.
Summary
CISA has identified a server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager Server, designated as CVE-2026-20230. This flaw allows attackers to execute arbitrary HTTP requests remotely without authentication. The agency added this vulnerability to its Known Exploited Vulnerabilities catalog and set an urgent deadline for remediation by June 28. Concurrently, CISA has also highlighted a critical remote code execution (RCE) vulnerability in PTC's Windchill and FlexPLM software, labeled CVE-2026-12569, which affects multiple versions of these product lifecycle management systems. Both vulnerabilities require immediate attention from federal agencies to prevent potential exploitation.
What Happened
The Cisco Unified Communications Manager Server flaw, CVE-2026-20230, is a server-side request forgery (SSRF) vulnerability that permits attackers to send specially crafted HTTP requests to the server. This can lead to unauthorized access and control over affected endpoints. Initially disclosed by Cisco on June 3, the company noted that while a proof-of-concept exploit existed, there was no evidence of active exploitation at that time. However, threat detection startup Defused later observed this vulnerability being exploited in attacks aimed at writing arbitrary text files to compromised systems.
Simultaneously, PTC's Windchill and FlexPLM software have been found vulnerable to CVE-2026-12569, an improper input validation flaw that allows remote code execution through the deserialization of untrusted data. This critical-severity vulnerability affects all versions up to 11.0 and various versions within the 11.1 to 13.0 release branches. PTC disclosed this issue on June 18 and urged customers to apply immediate remediation steps.
Affected Products and Fixed Versions
The Cisco Unified Communications Manager Server flaw impacts systems running vulnerable versions of the server software, which can be exploited remotely without authentication. Cisco released a patch for CVE-2026-20230 on June 3 to address this critical issue.
For PTC's Windchill and FlexPLM products, the RCE vulnerability affects all versions up to 11.0 and multiple versions within the 11.1, 11.2, 12.0, 12.1, and 13.0 release branches. PTC has provided guidance on vulnerable versions and recommended immediate patching or mitigation steps.
Exploitation Status
Both CVE-2026-20230 and CVE-2026-12569 are being actively exploited in the wild. The Cisco flaw was observed in attacks that allowed unauthorized writing of text files to affected endpoints. The type of threat actor exploiting these vulnerabilities remains unknown, underscoring the urgency for federal agencies and organizations to act swiftly.
Defender Guidance
Federal agencies and organizations using the affected Cisco Unified Communications Manager Server or PTC's Windchill and FlexPLM software must prioritize patching these vulnerabilities by June 28. For Cisco systems, apply the patch released on June 3 immediately. For PTC products, refer to the vendor's advisory for a complete list of vulnerable versions and follow the recommended remediation steps.
Additionally, organizations should conduct thorough security assessments to ensure all layers are tested against potential exploits. Implementing breach and attack simulation tools can help identify gaps in detection capabilities, ensuring that threats do not bypass existing defenses.
What Remains Unclear
While the vulnerabilities have been identified and patched, it remains unclear which threat actors are exploiting these flaws. Understanding the attackers' motives and methods could provide further insights into potential future risks and necessary defensive measures.
