On June 25, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two high-risk vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating evidence of active exploitation by threat actors. The vulnerabilities are CVE-2026-12569, affecting PTC products, and CVE-2026-20230, affecting a Cisco product. The inclusion in the KEV catalog triggers a requirement for U.S. Federal Civilian Executive Branch (FCEB) agencies to patch these flaws within a specific timeframe as mandated by Binding Operational Directive (BOD) 26-04. CISA's action serves as a strong recommendation for all public and private sector organizations to prioritize the remediation of these vulnerabilities to reduce their exposure to active cyber threats.
CVE-2026-12569 - PTC Windchill and FlexPLM Improper Input Validation Vulnerability:
CVE-2026-20230 - Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability:
T1595 - Active Scanning).WindchillFlexPLMUnified Communications ManagerOrganizations using these products should consult the respective vendor advisories for specific affected versions and patching information.
Both CVE-2026-12569 and CVE-2026-20230 are confirmed by CISA to be under active exploitation in the wild. This means that threat actors have developed working exploits and are actively using them to compromise vulnerable systems. The addition to the KEV catalog elevates the urgency of remediation far beyond that of a typical vulnerability disclosure. BOD 26-04 mandates that federal agencies not only patch these vulnerabilities but also check for signs of system compromise before applying the fix.
The active exploitation of these vulnerabilities poses a significant and immediate risk to organizations.
The following patterns may help identify vulnerable or compromised systems:
Web Application Firewall (WAF) LogsOutbound connections from server to internal IPsPTC Windchill/FlexPLM Application Logshttp://169.254.169.254M1035 - Limit Access to Resource Over Network).PTC flaw (CVE-2026-12569) reclassified as critical RCE. Cisco (CVE-2026-20230) details updated (CVSS 8.6, PoC, file write). CISA sets urgent June 28 deadline.
The PTC Windchill/FlexPLM vulnerability (CVE-2026-12569), initially described as improper input validation, is now confirmed as a critical Remote Code Execution (RCE) flaw stemming from deserialization of untrusted data. This significantly escalates its potential impact, allowing unauthenticated remote attackers to execute arbitrary code. For the Cisco Unified Communications Manager SSRF (CVE-2026-20230), new details include a CVSS score of 8.6 (High), observed exploitation by Defused, and the release of proof-of-concept code, enabling attackers to write arbitrary text files. CISA has issued an urgent deadline of June 28, 2026, for federal agencies to remediate both actively exploited flaws.
CISA adds CVE-2026-12569 and CVE-2026-20230 to the Known Exploited Vulnerabilities (KEV) catalog.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.