KEV: Lantronix, Ubiquiti UniFi OS, PTC Windchill and FlexPLM, and Cisco Unified Communications Manager
NEOSEC enrichment — no mirror of the original source
The US Cybersecurity and Infrastructure Security Agency (CISA) has added six CVEs to the Known Exploited Vulnerabilities (KEV) database so far this week; all six were assigned three-day mitigation windows. CVE-2025-67038 is a critical code
Source: SANS NewsBites. For licensing reasons NEOSEC Intel does not mirror the full text verbatim. Full body and expert context live with the original.
Editorial context in the original issue
The SANS NewsBites issue carries commentary by: Neely.
Linked advisories
- CVE-2025-67038Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability
- CVE-2025-67038lantronix e213f102s_firmware: Betriebssystem-Befehlsinjektion
- CVE-2026-34908A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to…
- CVE-2026-34908Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Access Control Vulnerability
- CVE-2026-34908ui enterprise_fortress_gateway_firmware: unzureichende Zugriffskontrolle
- CVE-2026-34908Ubiquiti UniFi OS Server: Mehrere Schwachstellen
- CVE-2026-20230Cisco Unified Communications Manager (CUCM): Schwachstelle ermöglicht Manipulation von Dateien
- CVE-2026-20230Cisco Unified Communications Manager — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
- CVE-2026-20230cisco unified_communications_manager: Server-Side-Request-Forgery (SSRF)
- CVE-2026-12569PTC Windchill and FlexPLM — PTC Windchill and FlexPLM Improper Input Validation Vulnerability
- CVE-2026-12569PTC FlexPLM: Schwachstelle ermöglicht Codeausführung
- CVE-2026-12569ptc flexplm: Deserialisierung nicht vertrauenswuerdiger Daten
- CVE-2026-34909A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system …
- CVE-2026-34909Ubiquiti UniFi OS — Ubiquiti UniFi OS Path Traversal Vulnerability
- CVE-2026-34909ui enterprise_fortress_gateway_firmware: Verzeichnisaufloesung (Path Traversal)
- CVE-2026-34910A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection.
- CVE-2026-34910Ubiquiti UniFi OS — Ubiquiti UniFi OS Improper Input Validation Vulnerability
- CVE-2026-34910ui enterprise_fortress_gateway_firmware: unzureichende Eingabevalidierung
More on FlexPLM
Other advisories
- CVE-2026-77646highPTC Windchill und FlexPLM: Mehrere Schwachstellen
- CVE-2026-12569criticalPTC FlexPLM: Schwachstelle ermöglicht Codeausführung
- CVE-2026-12569criticalptc flexplm: Deserialisierung nicht vertrauenswuerdiger Daten
- CVE-2026-12569criticalptc flexplm: Deserialisierung nicht vertrauenswuerdiger Daten
Other news entries
- Vulnerabilitybsi-cert-bund-wid2026-08-21PTC Windchill und FlexPLM: Mehrere Schwachstellen
- Newsthehackernews2026-08-19Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
- Newsbleepingcomputer2026-08-18Clop created custom web shell for Windchill data theft attacks
- Newsthehackernews2026-07-25Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
- Newsbleepingcomputer2026-07-24Clop ransomware targets Windchill, FlexPLM in data theft attacks
- Vulnerabilitysans-newsbites-mail2026-06-30Patch Now: Critical PTC Windchill Vulnerability
- Newscsoonline2026-06-26Hackers exploit critical PTC Windchill PLM software flaw
- Newsthehackernews2026-06-26CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
ID