discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog. The vulnerabilities are CVE-2026-12569 and CVE-2026-20230.

Jun 25·cisa.gov·2 min read

Intelligence analysis by Llama 3.3 70B

CISA's Known Exploited Vulnerabilities Catalog now includes two new vulnerabilities, posing significant risks to the federal enterprise. These vulnerabilities are frequent attack vectors for malicious cyber actors.

Why it matters

The addition of these vulnerabilities to the catalog highlights the importance of risk-based vulnerability management and prioritizing remediation of high-risk vulnerabilities. This affects not only federal agencies but also encourages all organizations to adopt similar practices.

CISA found two big security holes that bad people are using to hack into computers. They added these holes to a list so that companies and governments can fix them and stay safe.

Analysis

Introduction to Vulnerability Management

The Cybersecurity and Infrastructure Security Agency (CISA) has taken a significant step in enhancing cybersecurity by adding two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. This move is part of a broader effort to prioritize security updates based on risk, as outlined in Binding Operational Directive (BOD) 26-04. The directive emphasizes the importance of vulnerability management for Federal Civilian Executive Branch (FCEB) agencies, requiring them to prioritize the remediation of high-risk vulnerabilities, especially those that could grant total control of an asset post-exploitation.

Understanding the Added Vulnerabilities

The two vulnerabilities added to the catalog are CVE-2026-12569, related to PTC Windchill and FlexPLM Improper Input Validation, and CVE-2026-20230, concerning Cisco Unified Communications Manager Server-Side Request Forgery (SSRF). These vulnerabilities are notable because they are frequent attack vectors for malicious cyber actors, posing significant risks to the federal enterprise and potentially to other organizations. The inclusion of these vulnerabilities in the KEV Catalog underscores the need for proactive vulnerability management, especially for assets that are publicly exposed and could be exploited to gain total control.

Implications for Organizations

While BOD 26-04 specifically applies to FCEB agencies, CISA encourages all organizations to adopt a risk-based approach to vulnerability management. This involves prioritizing the remediation of vulnerabilities listed in the KEV Catalog, particularly those that have evidence of active exploitation. By doing so, organizations can significantly reduce their risk profile and protect against common attack vectors. The KEV Catalog serves as a critical resource for organizations looking to enhance their cybersecurity posture, providing a list of vulnerabilities that are known to be exploited by malicious actors. Organizations are also encouraged to submit vulnerabilities for potential addition to the catalog if they meet the specified criteria, including having a CVE ID, evidence of exploitation, and clear mitigation guidance.

Key points

  • CISA added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog.
  • The vulnerabilities are CVE-2026-12569 and CVE-2026-20230, related to PTC Windchill, FlexPLM, and Cisco Unified Communications Manager.
  • BOD 26-04 requires federal agencies to prioritize remediation of high-risk vulnerabilities.
The Upside

The proactive steps taken by CISA to update the KEV Catalog can lead to improved cybersecurity across the federal enterprise and beyond. By prioritizing the remediation of known exploited vulnerabilities, organizations can significantly reduce the risk of successful cyberattacks, leading to a safer digital environment.

The Downside

The addition of these vulnerabilities to the catalog also highlights the ongoing challenge of staying ahead of malicious cyber actors. If organizations fail to prioritize and remediate these vulnerabilities, they may remain exposed to significant risks, potentially leading to breaches and other cybersecurity incidents.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecurityvulnerability-management

Intelligence analysis by

Llama 3.3 70B

Published

Jun 25, 2026

Source

cisa.gov

Share

Topics

securitycybersecurityvulnerability-management

Related

More from this desk

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·bleepingcomputer.com

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings, without requiring organizer approval.

Aug 24·bleepingcomputer.com

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications. The issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework.

Aug 24·thehackernews.com

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.