Critical severity9.8CISA KEVNVD Advisory· Published Jun 18, 2026· Updated Aug 1, 2026
CVE-2026-12569
CVE-2026-12569
Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*range: <=11.0m030
- cpe:2.3:a:ptc:flexplm:11.1m020:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:flexplm:11.2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:flexplm:12.0.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:flexplm:12.0.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:flexplm:12.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:flexplm:13.0.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:flexplm:13.0.3.0:*:*:*:*:*:*:*
- (no CPE)range: <11.0 M030
cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*range: <11.0m030
- cpe:2.3:a:ptc:windchill_pdmlink:11.0m030:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:11.1m020:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:11.2.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:12.0.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:12.1.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:13.0.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:13.1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:13.1.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:13.1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ptc:windchill_pdmlink:13.1.3.0:*:*:*:*:*:*:*
- (no CPE)range: <11.0 M030
Patches
Vulnerability mechanics
References
2- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.ptc.com/en/support/article/CS473270nvdPermissions Required
News mentions
18- 24th August – Threat Intelligence ReportCheck Point Research · Aug 24, 2026
- The long tail of Clop’s PTC hack is just beginning to emergeCyberScoop · Aug 19, 2026
- Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignSecurityWeek · Aug 19, 2026
- Cl0p Hackers Exploit PTC Windchill Flaw to Steal Passwords and Sensitive Company DataCyber Security News · Aug 19, 2026
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering DataThe Hacker News · Aug 19, 2026
- Clop Claims Data Theft From More Than 40 CompaniesGovInfoSecurity · Aug 18, 2026
- Clop Tied to PTC Product Lifecycle Management Software HitsGovInfoSecurity · Jul 27, 2026
- PTC Windchill Vulnerability Exploited in Ransomware CampaignSecurityWeek · Jul 27, 2026
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThe Hacker News · Jul 25, 2026
- Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product DesignsCyber Security News · Jul 24, 2026
- Clop ransomware targets Windchill, FlexPLM in data theft attacksBleepingComputer · Jul 24, 2026
- Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security · Jul 5, 2026
- JSP webshells being dropped on unpatched PTC Windchill instancesHelp Net Security · Jun 29, 2026
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News · Jun 29, 2026
- CISA sets urgent deadline to fix Cisco flaw exploited in attacksBleepingComputer · Jun 26, 2026
- CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe Hacker News · Jun 26, 2026
- First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the WildSecurityWeek · Jun 26, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts