CISA added two newly exploited flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-12569 in PTC Windchill and FlexPLM and CVE-2026-20230 in Cisco Unified Communications Manager and Unified CM SME. The PTC issue is a critical unauthenticated remote code execution flaw tied to improper input validation or deserialization, affecting multiple Windchill and FlexPLM releases, while the Cisco issue is a critical server-side request forgery vulnerability that can be triggered through crafted HTTP requests when the WebDialer service is enabled. CISA set a June 28 remediation deadline for federal civilian agencies under its binding directive and urged broader review of exposed systems.
PTC said CVE-2026-12569 has now been confirmed exploited in the wild for the first time, with attackers reportedly deploying persistent JSP webshells for remote command execution and data exfiltration after sending specially crafted requests. PTC began releasing patches and mitigations earlier and later published indicators of compromise, while German police also warned organizations of imminent attacks. Cisco warned that public proof-of-concept code exists for CVE-2026-20230 and that successful exploitation could let attackers interact with internal services, write files to the underlying operating system, and potentially escalate privileges to root, raising concern for enterprises that rely on these communications and product lifecycle management platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Ransom-ISAC reported that starting on July 20, 2026, affiliates of the Cl0p ransomware group targeted Internet-exposed PTC Windchill and FlexPLM instances in a data-extortion campaign. The activity reportedly involved chaining a FlexPLM WSDL information-disclosure issue with unauthenticated RCE in the Windchill login servlet, followed by JSP web shell deployment, data exfiltration, and extortion emails sent to hundreds of users.
German police issued a warning to organizations about imminent attacks involving the PTC Windchill vulnerability. The warning was cited alongside reports of active exploitation activity.
PTC released indicators of compromise and said attackers were deploying persistent JSP webshells for remote command execution and data exfiltration on vulnerable systems. The company also said it had received reports of heightened threat activity.
CISA added CVE-2026-12569 to the KEV catalog as an actively exploited vulnerability and required federal civilian agencies to remediate by June 28, 2026. Reporting described this as the first confirmed in-the-wild exploitation of the PTC Windchill flaw.
CISA updated its Known Exploited Vulnerabilities catalog to add CVE-2026-12569 in PTC Windchill/FlexPLM and CVE-2026-20230 in Cisco Unified Communications Manager. The catalog update set a remediation due date of June 28, 2026 for both vulnerabilities.
PTC started publishing patches and mitigations for CVE-2026-12569, a remote code execution flaw affecting Windchill and FlexPLM. The vendor later also warned of active threat activity targeting the vulnerability.
Cisco released a patch for CVE-2026-20230, a critical unauthenticated SSRF vulnerability in Unified Communications Manager Server. Later reporting said the flaw was being actively exploited to write arbitrary text files to affected endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecyberveille.ch
Open sourceransom-isac.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourcecisa.gov
Open sourceptc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.