CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF - Critical Remote Code Execution Vulnerabilities
CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF (TL-2026-0971), also tracked as PTC Windchill KEV Exploitation, is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-06-28. It has no confirmed attribution, affects PTC Windchill PDMLink, references 2 CVEs (CVE-2026-12569, CVE-2026-20230), maps to 27 MITRE ATT&CK techniques (T1005, T1016, T1036), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0971
- Threat ID
- TL-2026-0971
- Also known as
- PTC Windchill KEV Exploitation, Cisco Unified CM SSRF Chain
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-06-28
- Last reviewed
- 2026-06-28
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- manufacturing, aerospace, defense, government-federal, communications, enterprise-it, critical-infrastructure
- Target regions
- north-america, europe, asia-pacific
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
Malware and tooling: Beacon callbacks from compromised Windchill/UCM systems to attacker C2 infrastructure
CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities Catalog on June 25, 2026: CVE-2026-12569 (PTC Windchill deserialization RCE) and CVE-2026-20230 (Cisco Unified CM SSRF with privilege escalation). Both pose immediate risk to federal enterprise and critical infrastructure with active exploitation confirmed.
How CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF works
On June 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical remote code execution vulnerabilities to its Known Exploited Vulnerabilities Catalog, signaling widespread active exploitation in the wild. CVE-2026-12569 affects PTC Windchill PDMLink and FlexPLM—enterprise product lifecycle management platforms used across manufacturing, aerospace, and defense sectors—through improper input validation enabling deserialization of untrusted data. CVE-2026-20230 affects Cisco Unified Communications Manager (UCM), a core enterprise voice/communications platform, via a server-side request forgery (SSRF) vulnerability that chains to unauthenticated remote code execution and root privilege escalation when the WebDialer service is enabled.
Both vulnerabilities represent post-exploitation control risks requiring immediate patching or air-gapping per CISA's BOD 26-04 prioritization directive. The Windchill vulnerability leverages unsafe Java/dotnet deserialization gadget chains to execute arbitrary code on systems lacking patching, affecting versions from 11.0 M030 through 13.1.3.0. The Cisco SSRF vulnerability allows unauthenticated attackers to write arbitrary files to the underlying operating system, enabling local privilege escalation to root and complete system compromise of the communications infrastructure.
Active exploitation has been confirmed by CISA and independent security researchers, with public proof-of-concept analysis available. Enterprise defenders must immediately assess internet exposure of both platforms, apply vendor patches, and enforce network segmentation to isolate potentially compromised systems. Both vulnerabilities are automatable (except Cisco SSRF manual interaction requirement) and carry the highest technical impact—total confidentiality, integrity, and availability breach of the targeted systems and downstream lateral movement.
MITRE ATT&CK techniques used in TL-2026-0971
Collection
T1005 Data from Local System; T1113 Screen Capture
Discovery
T1016 System Network Configuration Discovery; T1518 Software Discovery
Defense Evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution
Command and Control
T1102 Web Service; T1219 Remote Access Tools; T1573 Encrypted Channel
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery; T1496 Resource Hijacking; T1531 Account Access Removal
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Lateral Movement
T1563 Remote Service Session Hijacking; T1570 Lateral Tool Transfer
resource-development
defense-impairment
Affected products and versions in CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
- PTC — Windchill PDMLink
Vulnerable versions: <11.0 M030; 11.0 M030; 11.1 M020; 11.2.1.0; 12.0.2.0; 12.1.2.0; 13.0.2.0; 13.1.0.0; 13.1.1.0; 13.1.2.0
Fixed in: 14.0.0.0 and later (if released) - PTC — FlexPLM
Vulnerable versions: <11.0 M030; 11.0 M030; 11.1 M020; 11.2.1.0; 12.0.0.0; 12.0.2.0; 12.1.2.0; 12.1.3.0; 13.0.2.0; 13.0.3.0
Fixed in: 13.1.0.0 and later (if available) - Cisco — Unified Communications Manager (Unified CM)
Vulnerable versions: 14.0 through 14su5; 15.0 through 15su4a
Fixed in: 14su6 and later; 15su4b and later - Cisco — Unified Communications Manager Session Management Edition (Unified CM SME)
Vulnerable versions: 14.0 through 14su5; 15.0 through 15su4a
Fixed in: 14su6 and later; 15su4b and later
Remediation for CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
Patches
- PTC Windchill/FlexPLM: Apply patch from PTC Support Article CS473270 (vendor-supplied patch)
- Cisco Unified CM: Upgrade to 14su6 or later (14.0 branch) or 15su4a or later (15.0 branch)
Immediate actions
- Apply PTC security patches immediately (CS473270 and vendor-supplied hotfixes) to all Windchill/FlexPLM instances
- Apply Cisco patches to Unified CM (14su6, 15su4a or later) across all instances
- Disable WebDialer service on Cisco Unified CM if not required (default disabled, verify settings)
- Block internet-facing ports 8443 (Windchill), 8080-8088 (Cisco UCM) at perimeter firewalls
- Enable network segmentation to isolate Windchill and UCM systems from general enterprise networks
- Monitor all outbound SSRF/callback attempts from potentially compromised systems
- Perform forensic analysis on systems running vulnerable versions for evidence of exploitation (file writes, process injection, scheduled tasks)
Workarounds
- Cisco SSRF: Disable WebDialer service if not in use (disable via CUCM admin web interface under Device > Device Settings)
- Windchill: If patching delayed, implement WAF rules blocking POST requests with serialized Java/dotnet payloads (gadget chain signatures)
- Both: Restrict network access to admin interfaces (8443 Windchill, 8080 Cisco) to authenticated corporate networks only
Longer-term hardening
- Implement zero-trust architecture for voice/communications and PLM infrastructure
- Deploy behavioral EDR/XDR with deserialization-gadget-chain detection across manufacturing/engineering networks
- Establish continuous vulnerability scanning for internet-exposed Windchill, FlexPLM, and Cisco Unified CM instances
- Require multi-factor authentication on all administrative access to PLM and communications platforms
- Implement air-gapping or VPN-only access for Windchill/FlexPLM external access if internet exposure required
- Establish patching SLAs: critical vulns ≤1 week, within VLANs ≤2 weeks per CISA BOD 26-04
CVEs associated with CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
Weaknesses (CWE) in CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
CWE-502, CWE-20, CWE-918
Timeline of CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
- PTC and Cisco initiate responsible disclosure process with vendors; vulnerabilities reported to security teams; patch development begins
- Cisco and PTC patch teams complete initial testing; security fixes prepared for release; CISA coordination begins for KEV coordination
- Cisco publishes security advisory for CVE-2026-20230 (Unified CM SSRF vulnerability); patched versions (14su6, 15su4b) released; independent PoC research publication begins
- Security researchers and threat intelligence feeds report mass scanning activity targeting Cisco Unified CM port 8080/8088 (WebDialer); evidence of active reconnaissance across internet-exposed instances
- Independent security researcher (DenizHalil) publishes detailed technical analysis of CVE-2026-20230 SSRF-to-RCE exploitation chain and root privilege escalation mechanics; full exploitation walkthrough available online
- PTC issues urgent security notice for CVE-2026-12569 (Windchill/FlexPLM deserialization RCE); patch development in final testing phase; remediation guidance published
- PTC publishes vulnerability notice and patches for CVE-2026-12569 (support article CS473270); NVD records published for both CVEs with CVSS scores and configuration details
- CISA and vendor teams investigate scope of active exploitation; evidence suggests both vulnerabilities exploited in coordinated campaigns targeting federal systems and critical infrastructure; attribution to financially-motivated threat actors suspected
- CISA adds both CVE-2026-12569 and CVE-2026-20230 to Known Exploited Vulnerabilities (KEV) Catalog; SSVC: exploitation=active, automatable=yes/no, technicalImpact=total; federal agencies and critical infrastructure operators put on highest alert
- NVD records updated with CISA SSVC ratings and exploitation confirmation; lastModified timestamps reflect finalization of threat severity assessment and remediation requirements
- Security firms report active exploitation campaigns in the wild using both CVEs; ransomware operators and financially-motivated threat actors observed targeting manufacturing, aerospace, defense, and communications sectors; post-exploitation backdoors installed
- CISA deadline (3-day remediation window expires) for federal agencies and critical infrastructure operators to patch or isolate affected systems per BOD 26-04 prioritization; forensics triage required for potential compromises; incident response posture elevated to peak
Sources cited for CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (Alert)
- CVE-2026-12569 - NVD National Vulnerability Database
- CVE-2026-20230 - NVD National Vulnerability Database
- Cisco Security Advisory - Unified CM SSRF Vulnerability
- PTC Windchill Security Patch - Support Article CS473270
- CVE-2026-20230: Cisco Unified CM SSRF & Root Exploit Analysis
- CISA Known Exploited Vulnerabilities (KEV) Catalog - CVE-2026-12569
- CISA Known Exploited Vulnerabilities (KEV) Catalog - CVE-2026-20230
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk
- CISA Forensics Triage Requirements - BOD 26-04 Implementation Guidance
Threats related to CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF
- CISA KEV: Cisco Unified Communications Manager SSRF to Webshell (CVE-2026-20230) Actively Exploited
- CISA KEV Adds CVE-2026-12569 (PTC Windchill/FlexPLM Unauthenticated RCE via Deserialization) and CVE-2026-20230 (Cisco Unified CM WebDialer SSRF to Root)
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)
- Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245)
- CVE-2026-20230: Cisco Unified Communications Manager WebDialer SSRF Actively Exploited to Drop Tor-Routed JSP Webshells via Rogue Apache Axis Service, CISA Sets June 28 Deadline
- CVE-2026-12569: PTC Windchill PDMLink / FlexPLM Unauthenticated Deserialization RCE (CISA KEV, JSP Web Shell Campaign)
Detection coverage for TL-2026-0971
As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0971 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.