VYPR
Critical severity9.8CISA KEVNVD Advisory· Published Jun 18, 2026· Updated Aug 1, 2026

CVE-2026-12569

CVE-2026-12569

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

21
  • Ptc/FlexPLM9 versions
    cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*range: <=11.0m030
    • cpe:2.3:a:ptc:flexplm:11.1m020:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:flexplm:11.2.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:flexplm:12.0.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:flexplm:12.0.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:flexplm:12.1.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:flexplm:13.0.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:flexplm:13.0.3.0:*:*:*:*:*:*:*
    • (no CPE)range: <11.0 M030
  • cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*+ 11 more
    • cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*range: <11.0m030
    • cpe:2.3:a:ptc:windchill_pdmlink:11.0m030:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:11.1m020:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:11.2.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:12.0.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:12.1.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:13.0.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:13.1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:13.1.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:13.1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ptc:windchill_pdmlink:13.1.3.0:*:*:*:*:*:*:*
    • (no CPE)range: <11.0 M030

Patches

Vulnerability mechanics

References

2

News mentions

18