Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Black Hat Asia 2026 | Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices

    August 27, 2026

    CIS and SANS: A Longstanding Partnership Built to Advance Cybersecurity

    August 26, 2026

    Podcast: Cops Are Making Fake Flock Cameras and Amazon Packages

    August 26, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»CISA sets urgent deadline to fix Cisco flaw exploited in attacks
    News

    CISA sets urgent deadline to fix Cisco flaw exploited in attacks

    adminBy adminJune 26, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    CISA sets urgent deadline to fix Cisco flaw exploited in attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited.

    Identified as CVE-2026-20230, the security issue is server-side request forgery (SSRF) and has been added to the agency’s catalog of Known Exploited Vulnerabilities (KEV).

    Per Binding Operational Directive (BOD) 26-04, the remediation is deemed urgent and must addressed by Sunday, June 28.

    image

    Cisco marked CVE-2026-20230 with critical severity and released a patch on June 3, warning that it could be exploited remotely and without authentication via specially crafted HTTP requests.

    At the time, the company noted that a proof-of-concept exploit existed, but had found no evidence of active exploitation.

    Last weekend, threat detection startup Defused observed the vulnerability being exploited in attacks to write arbitrary text files to affected endpoints.

    It is currently unknown what type of threat actor is leveraging CVE-2026-20230 in attacks.

    Critical flaw in PLM products

    CISA has also added CVE-2026-12569 to the KEV catalog, an improper input validation flaw impacting the PTC Windchill and FlexPLM software products.

    Both are product lifecycle management (PLM) systems developed by PTC specifically for the manufacturing, engineering, retail, footwear, apparel, and consumer products industries.

    CVE-2026-12569 is a critical-severity remote code execution (RCE) vulnerability that can be exploited through the deserialization of untrusted data.

    PTC disclosed the issue on June 18 and published a security advisory, pointing customers to the complete list of vulnerable Windchill and FlexPLM versions and urging them to immediately take remediation steps.

    According to the vendor, the flaw affects all versions up to 11.0 and multiple versions of the 11.1, 11.2, 12.0, 12.1, and 13.0 release branches.

    CISA set the same June 28 deadline for federal agencies to patch CVE-2026-12569.

    Agencies and organizations bound by BOD 26-04 should take immediate action to secure their systems by applying available security updates and vendor-recommended mitigations, or stop using the products mentioned by the set deadline.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFBI: Russian hackers now target Signal backup recovery keys
    Next Article Cybersecurity firms targeted by fraudulent OpenAI organization invites
    admin
    • Website

    Related Posts

    News

    CIS and SANS: A Longstanding Partnership Built to Advance Cybersecurity

    August 26, 2026
    News

    Podcast: Cops Are Making Fake Flock Cameras and Amazon Packages

    August 26, 2026
    News

    Inside the Warehouse Where Amazon Scans and Destroys Books for AI Training

    August 26, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Black Hat Asia 2026 | Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices

    August 27, 2026

    CIS and SANS: A Longstanding Partnership Built to Advance Cybersecurity

    August 26, 2026

    Podcast: Cops Are Making Fake Flock Cameras and Amazon Packages

    August 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.