Our takeCISA added CVE-2026-12569 (PTC Windchill/FlexPLM input validation) and CVE-2026-20230 (Cisco Unified CM SSRF) to KEV. Patch if you run them (enterprises, MSPs); most smaller shops don't deploy this software and can ignore it.Cyber Resilience desk
Sources (8)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Patch CVE-2026-12569 (PTC Windchill/FlexPLM), CVE-2026-20230 (Cisco Unified CM SSRF), CVE-2026-48558 (SimpleHelp auth bypass), CVE-2026-45659 (SharePoint deserialization), CVE-2026-48282 (ColdFusion path traversal), and the older CVE-2008-4128 (Cisco IOS CSRF) immediately if present in your environment.
What this means for you — Lean IT orgs:If you use PTC Windchill, Cisco Unified CM, SimpleHelp, SharePoint Server, Adobe ColdFusion, or older Cisco IOS gear, apply the vendor patches right away; most small teams without these products can ignore this update.
What this means for you — MSP:Check client estates for PTC Windchill/FlexPLM, Cisco Unified CM, SimpleHelp, SharePoint Server, Adobe ColdFusion, and legacy Cisco IOS; push the published patches and verify they are no longer reachable from the internet.
What this means for you — Researcher:CISA added CVE-2026-12569, CVE-2026-20230, CVE-2026-48558, CVE-2026-45659, CVE-2026-48282 and CVE-2008-4128 to KEV based on confirmed in-the-wild exploitation.