CISA orders US federal agencies to patch critical Cisco Unified CM flaw by June 28
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a binding operational directive requiring all federal agencies to install patches for a critical server‑side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager (CVE‑2026‑20230) no later than Sunday, June 28. Cisco rated the flaw as critical and released a fix on June 3; the vulnerability allows unauthenticated attackers to write arbitrary files to the operating system and potentially gain root‑level control. The threat‑detection firm Defused reported active exploitation of the flaw in the wild, though the specific threat actor remains unidentified.
In the same directive, CISA added a second critical issue – CVE‑2026‑12569 – affecting PTC Windchill and FlexPLM product‑lifecycle‑management software. This remote‑code‑execution vulnerability also carries a June 28 remediation deadline for agencies bound by the directive. Both vulnerabilities are listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, and agencies are instructed to apply vendor patches immediately or discontinue use of the affected products.
CISA advises agencies to verify patch deployment, conduct forensic triage for signs of compromise, and audit logs for suspicious activity as part of the emergency response.