VulnerabilityBleeping Computer
9.8 — CRITICAL
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Two vulnerabilities, CVE-2026-20230 and CVE-2026-12569, have been identified in Cisco Unified Communications Manager Server and PTC Windchill FlexPLM software respectively, which are being actively exploited in attacks to write arbitrary text files or execute remote code. These vulnerabilities can be exploited remotely without authentication via specially crafted HTTP requests.
⚙️Technical Details
💥Impact Assessment
Severity: Unknown
🛡️Recommended Actions
1Apply available security updates for Cisco Unified Communications Manager Server and PTC Windchill FlexPLM software
2Implement vendor-recommended mitigations for both vulnerabilities
3Stop using affected products by the set deadline
📦Affected Products
Cisco Unified Communications ManagerPtc FlexplmPtc Windchill PdmlinkCisco Unified Communications Manager ServerPTC Windchill FlexPLM
🔐NVD Verified DataVERIFIED
CVE-2026-20230 ↗CVSS 8.6 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NWeaknesses
CWE-918
Affected Products (CPE)
Cisco Unified Communications Manager
CVE-2026-12569 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-20CWE-502
Affected Products (CPE)
Ptc FlexplmPtc Windchill Pdmlink
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
