Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-77645PATCHED
ptc · windchill pdmlink

Critical Remote Code Execution (RCE) vulnerability reported in Windchill

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

Affected Products

VendorProductVersions
ptcwindchill pdmlink11.0 M030, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0, 11.0 M030, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.0.3.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ptcwindchillcert_advisory90%
ptcptc flexplmcert_advisory90%

References

  • https://www.ptc.com/en/support/article/CS474826(vendor-advisory, mitigation, permissions-required)

Related News (2 articles)

Tier B
BSI Advisories2d ago
[NEU] [hoch] PTC Windchill und FlexPLM: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-77645 | PTC Windchill/FlexPLM input validation
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.ptc.com/en/support/article/CS474826
CWECWE-20, CWE-502
PublishedAug 20, 2026
Trending Score25
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (3)

NONECVE-2026-12569EXPKEV
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
Trending: 80
NONECVE-2026-77646EXP
Server Side Request Forgery (SSRF) vulnerability reported in Windchill
Trending: 39
NONECVE-2026-77644
Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 20, 2026
Discovered by ZDM
Aug 20, 2026
Patch Available
Aug 22, 2026