Monday, June 29, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Monday's disclosures concentrate on network edge and enterprise communications platforms, led by multiple Ubiquiti UniFi OS flaws, a Cisco Unified Communications Manager defect, and PTC Windchill/FlexPLM. No new critical-rated (CVSS 9.0+) CVEs were recorded, down from 1 the prior day, while high-priority CVEs fell to 24 from 55, a 56% decrease. Notable entries include CVE-2026-34910, CVE-2026-34909, and CVE-2026-34908 affecting Ubiquiti UniFi OS, CVE-2026-20230 in Cisco Unified CM, and CVE-2026-12569 in PTC Windchill and FlexPLM, all scored 9.5. Six of these vulnerabilities carry confirmed active exploitation, spanning network appliances, IoT device servers, and PLM systems. No patches were available across the disclosed set at publication time, so affected organizations should prioritize monitoring and compensating controls until vendor fixes ship.

  • Ubiquiti UniFi OS is the most affected platform, with three actively exploited flaws (CVE-2026-34910, CVE-2026-34909, CVE-2026-34908) each scored CVSS 9.5
  • Zero new critical-rated CVEs, down 100% from 1 the prior day
  • 24 high-priority CVEs, down 56% from 55 the prior day
  • Exploitation activity targets network and communications infrastructure, including Cisco Unified CM (CVE-2026-20230) and PTC Windchill/FlexPLM (CVE-2026-12569)
  • Patch availability stands at 0% across the disclosed set, leaving affected systems reliant on mitigations
  • Six vulnerabilities have confirmed active exploitation, also including Lantronix EDS5000 (CVE-2025-67038)

Immediate action: Prioritize Ubiquiti UniFi OS, Cisco Unified Communications Manager, PTC Windchill/FlexPLM, and Lantronix EDS5000 deployments, as these carry actively exploited vulnerabilities. With no patches currently available, restrict network exposure of these systems, apply vendor-recommended mitigations, and increase monitoring until fixes are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation