CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF - Critical Remote Code Execution Vulnerabilities

CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF (TL-2026-0971), also tracked as PTC Windchill KEV Exploitation, is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-06-28. It has no confirmed attribution, affects PTC Windchill PDMLink, references 2 CVEs (CVE-2026-12569, CVE-2026-20230), maps to 27 MITRE ATT&CK techniques (T1005, T1016, T1036), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0971

Threat ID
TL-2026-0971
Also known as
PTC Windchill KEV Exploitation, Cisco Unified CM SSRF Chain
Severity
CRITICAL
CVSS
9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-06-28
Last reviewed
2026-06-28
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
manufacturing, aerospace, defense, government-federal, communications, enterprise-it, critical-infrastructure
Target regions
north-america, europe, asia-pacific
Detection rules
9
Indicators of compromise
20

Malware and tooling in CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

Malware and tooling: Beacon callbacks from compromised Windchill/UCM systems to attacker C2 infrastructure

CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities Catalog on June 25, 2026: CVE-2026-12569 (PTC Windchill deserialization RCE) and CVE-2026-20230 (Cisco Unified CM SSRF with privilege escalation). Both pose immediate risk to federal enterprise and critical infrastructure with active exploitation confirmed.

How CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF works

On June 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical remote code execution vulnerabilities to its Known Exploited Vulnerabilities Catalog, signaling widespread active exploitation in the wild. CVE-2026-12569 affects PTC Windchill PDMLink and FlexPLM—enterprise product lifecycle management platforms used across manufacturing, aerospace, and defense sectors—through improper input validation enabling deserialization of untrusted data. CVE-2026-20230 affects Cisco Unified Communications Manager (UCM), a core enterprise voice/communications platform, via a server-side request forgery (SSRF) vulnerability that chains to unauthenticated remote code execution and root privilege escalation when the WebDialer service is enabled.

Both vulnerabilities represent post-exploitation control risks requiring immediate patching or air-gapping per CISA's BOD 26-04 prioritization directive. The Windchill vulnerability leverages unsafe Java/dotnet deserialization gadget chains to execute arbitrary code on systems lacking patching, affecting versions from 11.0 M030 through 13.1.3.0. The Cisco SSRF vulnerability allows unauthenticated attackers to write arbitrary files to the underlying operating system, enabling local privilege escalation to root and complete system compromise of the communications infrastructure.

Active exploitation has been confirmed by CISA and independent security researchers, with public proof-of-concept analysis available. Enterprise defenders must immediately assess internet exposure of both platforms, apply vendor patches, and enforce network segmentation to isolate potentially compromised systems. Both vulnerabilities are automatable (except Cisco SSRF manual interaction requirement) and carry the highest technical impact—total confidentiality, integrity, and availability breach of the targeted systems and downstream lateral movement.

MITRE ATT&CK techniques used in TL-2026-0971

Collection

T1005 Data from Local System; T1113 Screen Capture

Discovery

T1016 System Network Configuration Discovery; T1518 Software Discovery

Defense Evasion

T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1203 Exploitation for Client Execution

Command and Control

T1102 Web Service; T1219 Remote Access Tools; T1573 Encrypted Channel

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery; T1496 Resource Hijacking; T1531 Account Access Removal

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Lateral Movement

T1563 Remote Service Session Hijacking; T1570 Lateral Tool Transfer

resource-development

T1588 Obtain Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

  • PTC — Windchill PDMLink
    Vulnerable versions: <11.0 M030; 11.0 M030; 11.1 M020; 11.2.1.0; 12.0.2.0; 12.1.2.0; 13.0.2.0; 13.1.0.0; 13.1.1.0; 13.1.2.0
    Fixed in: 14.0.0.0 and later (if released)
  • PTC — FlexPLM
    Vulnerable versions: <11.0 M030; 11.0 M030; 11.1 M020; 11.2.1.0; 12.0.0.0; 12.0.2.0; 12.1.2.0; 12.1.3.0; 13.0.2.0; 13.0.3.0
    Fixed in: 13.1.0.0 and later (if available)
  • Cisco — Unified Communications Manager (Unified CM)
    Vulnerable versions: 14.0 through 14su5; 15.0 through 15su4a
    Fixed in: 14su6 and later; 15su4b and later
  • Cisco — Unified Communications Manager Session Management Edition (Unified CM SME)
    Vulnerable versions: 14.0 through 14su5; 15.0 through 15su4a
    Fixed in: 14su6 and later; 15su4b and later

Remediation for CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

Patches

  • PTC Windchill/FlexPLM: Apply patch from PTC Support Article CS473270 (vendor-supplied patch)
  • Cisco Unified CM: Upgrade to 14su6 or later (14.0 branch) or 15su4a or later (15.0 branch)

Immediate actions

  • Apply PTC security patches immediately (CS473270 and vendor-supplied hotfixes) to all Windchill/FlexPLM instances
  • Apply Cisco patches to Unified CM (14su6, 15su4a or later) across all instances
  • Disable WebDialer service on Cisco Unified CM if not required (default disabled, verify settings)
  • Block internet-facing ports 8443 (Windchill), 8080-8088 (Cisco UCM) at perimeter firewalls
  • Enable network segmentation to isolate Windchill and UCM systems from general enterprise networks
  • Monitor all outbound SSRF/callback attempts from potentially compromised systems
  • Perform forensic analysis on systems running vulnerable versions for evidence of exploitation (file writes, process injection, scheduled tasks)

Workarounds

  • Cisco SSRF: Disable WebDialer service if not in use (disable via CUCM admin web interface under Device > Device Settings)
  • Windchill: If patching delayed, implement WAF rules blocking POST requests with serialized Java/dotnet payloads (gadget chain signatures)
  • Both: Restrict network access to admin interfaces (8443 Windchill, 8080 Cisco) to authenticated corporate networks only

Longer-term hardening

  • Implement zero-trust architecture for voice/communications and PLM infrastructure
  • Deploy behavioral EDR/XDR with deserialization-gadget-chain detection across manufacturing/engineering networks
  • Establish continuous vulnerability scanning for internet-exposed Windchill, FlexPLM, and Cisco Unified CM instances
  • Require multi-factor authentication on all administrative access to PLM and communications platforms
  • Implement air-gapping or VPN-only access for Windchill/FlexPLM external access if internet exposure required
  • Establish patching SLAs: critical vulns ≤1 week, within VLANs ≤2 weeks per CISA BOD 26-04

CVEs associated with CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

CVE-2026-12569, CVE-2026-20230

Weaknesses (CWE) in CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

CWE-502, CWE-20, CWE-918

Timeline of CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

  • PTC and Cisco initiate responsible disclosure process with vendors; vulnerabilities reported to security teams; patch development begins
  • Cisco and PTC patch teams complete initial testing; security fixes prepared for release; CISA coordination begins for KEV coordination
  • Cisco publishes security advisory for CVE-2026-20230 (Unified CM SSRF vulnerability); patched versions (14su6, 15su4b) released; independent PoC research publication begins
  • Security researchers and threat intelligence feeds report mass scanning activity targeting Cisco Unified CM port 8080/8088 (WebDialer); evidence of active reconnaissance across internet-exposed instances
  • Independent security researcher (DenizHalil) publishes detailed technical analysis of CVE-2026-20230 SSRF-to-RCE exploitation chain and root privilege escalation mechanics; full exploitation walkthrough available online
  • PTC issues urgent security notice for CVE-2026-12569 (Windchill/FlexPLM deserialization RCE); patch development in final testing phase; remediation guidance published
  • PTC publishes vulnerability notice and patches for CVE-2026-12569 (support article CS473270); NVD records published for both CVEs with CVSS scores and configuration details
  • CISA and vendor teams investigate scope of active exploitation; evidence suggests both vulnerabilities exploited in coordinated campaigns targeting federal systems and critical infrastructure; attribution to financially-motivated threat actors suspected
  • CISA adds both CVE-2026-12569 and CVE-2026-20230 to Known Exploited Vulnerabilities (KEV) Catalog; SSVC: exploitation=active, automatable=yes/no, technicalImpact=total; federal agencies and critical infrastructure operators put on highest alert
  • NVD records updated with CISA SSVC ratings and exploitation confirmation; lastModified timestamps reflect finalization of threat severity assessment and remediation requirements
  • Security firms report active exploitation campaigns in the wild using both CVEs; ransomware operators and financially-motivated threat actors observed targeting manufacturing, aerospace, defense, and communications sectors; post-exploitation backdoors installed
  • CISA deadline (3-day remediation window expires) for federal agencies and critical infrastructure operators to patch or isolate affected systems per BOD 26-04 prioritization; forensics triage required for potential compromises; incident response posture elevated to peak

Sources cited for CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

Threats related to CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF

Detection coverage for TL-2026-0971

As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0971 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats