---
title: "CISA sets urgent deadline to fix Cisco flaw exploited in attacks"
url: https://daily.dev/posts/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks-dfknamsxp
source_url: https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks
type: article
source: "BleepingComputer"
published: 2026-06-26T19:46:42.133Z
updated: 2026-08-24T06:55:54.459Z
tags: ["security", "cisco"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA sets urgent deadline to fix Cisco flaw exploited in attacks

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 2 min read · 0 upvotes · 0 comments

## Summary

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog and set a June 28 deadline for federal agencies to patch them. The first, CVE-2026-20230, is a critical SSRF flaw in Cisco Unified Communications Manager that can be exploited remotely without authentication via crafted HTTP requests; active exploitation was observed writing arbitrary files to affected endpoints. The second, CVE-2026-12569, is a critical RCE vulnerability in PTC Windchill and FlexPLM PLM products caused by deserialization of untrusted data, affecting all versions up to 11.0 and multiple branches through 13.0. Agencies must patch or stop using the affected products by the deadline under Binding Operational Directive 26-04.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks>

---

Tags: [#security](https://daily.dev/tags/security), [#cisco](https://daily.dev/tags/cisco)

[View this post on daily.dev](https://daily.dev/posts/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks-dfknamsxp)
