VulnerabilitySANS NewsBites2026-06-24 00:00 UTCICS / OT (industrial control)SME

KEV: Lantronix, Ubiquiti UniFi OS, PTC Windchill and FlexPLM, and Cisco Unified Communications Manager

NEOSEC enrichment — no mirror of the original source

The US Cybersecurity and Infrastructure Security Agency (CISA) has added six CVEs to the Known Exploited Vulnerabilities (KEV) database so far this week; all six were assigned three-day mitigation windows. CVE-2025-67038 is a critical code

Source: SANS NewsBites. For licensing reasons NEOSEC Intel does not mirror the full text verbatim. Full body and expert context live with the original.

Editorial context in the original issue

The SANS NewsBites issue carries commentary by: Neely.

ID