Unrated severityCISA KEVNVD Advisory· Published Jun 18, 2026
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
CVE-2026-12569
Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Affected products
2- Range: <11.0 M030
Patches
Vulnerability mechanics
References
1- www.ptc.com/en/support/article/CS473270mitrevendor-advisorymitigationpermissions-required
News mentions
12- Clop Tied to PTC Product Lifecycle Management Software HitsGovInfoSecurity · Jul 27, 2026
- PTC Windchill Vulnerability Exploited in Ransomware CampaignSecurityWeek · Jul 27, 2026
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThe Hacker News · Jul 25, 2026
- Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product DesignsCyber Security News · Jul 24, 2026
- Clop ransomware targets Windchill, FlexPLM in data theft attacksBleepingComputer · Jul 24, 2026
- Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security · Jul 5, 2026
- JSP webshells being dropped on unpatched PTC Windchill instancesHelp Net Security · Jun 29, 2026
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and MoreThe Hacker News · Jun 29, 2026
- CISA sets urgent deadline to fix Cisco flaw exploited in attacksBleepingComputer · Jun 26, 2026
- CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks ContinueThe Hacker News · Jun 26, 2026
- First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the WildSecurityWeek · Jun 26, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts