radar.cysentrix
10 reports · 7 sources · tracked since 2d ago Actively exploited

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

AI synthesis CISA added exploited PTC Windchill RCE and Cisco Unified CM SSRF flaws to its KEV catalog amid ongoing web shell attacks.

Why this ranks Transparent score: 54 Editorially featured by AI
coverage +30 source breadth +14 urgency +6 freshness +4

What changed

Coverage timeline

Every report remains linked to its original publisher.

  1. SecurityWeek Coverage expanded

    Hackers Exploiting Cisco Unified CM Vulnerability ↗

    Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. The post Hackers Exploiting Cisco Unified CM Vulnerability appeared first on SecurityWeek.

  2. The Hacker News Coverage expanded

    Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root ↗

    Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score:...

  3. Help Net Security Coverage expanded

    Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) ↗

    CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated swe...

  4. Security Affairs Coverage expanded

    Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild ↗

    Attackers exploit Cisco Unified CM flaw (CVE-2026-20230) allowing unauth HTTP requests to trigger SSRF, write files, and gain root access Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already...

  5. CISA Alerts Coverage expanded

    CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Server-Si...

  6. The Hacker News Coverage expanded

    CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue ↗

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Kno...