Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-12569KEVEXPLOITEDPATCHED
ptc · flexplm

Remote Code Execution (RCE) vulnerability in Windchill PDMlink

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Affected Products

VendorProductVersions
ptcflexplm0, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0, 0, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ptcptc flexplmcert_advisory90%
ptcptc windchillcert_advisory90%
ptcwindchill_pdmlinkcve_cpe95%

References

  • https://www.ptc.com/en/support/article/CS473270(vendor-advisory, mitigation, permissions-required)

Related News (16 articles)

Tier D
SecurityWeek4d ago
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
→ No new info (linked only)
Tier D
The Hacker News5d ago
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
→ No new info (linked only)
Tier D
BleepingComputer5d ago
Clop created custom web shell for Windchill data theft attacks
→ No new info (linked only)
Tier D
BleepingComputer9d ago
Shell investigates 'potential incident' after Clop data theft claims
→ No new info (linked only)
Tier D
SecurityWeek27d ago
PTC Windchill Vulnerability Exploited in Ransomware Campaign
→ No new info (linked only)
Tier D
The Hacker News29d ago
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
→ No new info (linked only)
Tier D
BleepingComputer30d ago
Clop ransomware targets Windchill, FlexPLM in data theft attacks
→ No new info (linked only)
Tier D
Help Net Security55d ago
JSP webshells being dropped on unpatched PTC Windchill instances
→ No new info (linked only)
Tier D
CSO Online58d ago
Hackers exploit critical PTC Windchill PLM software flaw
→ No new info (linked only)
Tier D
The Hacker News58d ago
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
→ No new info (linked only)
Tier E
Reddit r/cybersecurity58d ago
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
→ No new info (linked only)
Tier D
SecurityWeek58d ago
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
→ No new info (linked only)
Tier D
Heise Security65d ago
PTC Windchill: BSI ruft Admins nachts wegen kritischer Sicherheitslücke an
→ No new info (linked only)
Tier B
BSI Advisories66d ago
[NEU] [UNGEPATCHT] [kritisch] PTC FlexPLM: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier C
VulDB67d ago
CVE-2026-12569 | PTC Windchill PDMLink/FlexPLM up to 13.1.3.0 input validation
→ No new info (linked only)
Tier B
CCCS Canada150d ago
PTC security advisory (AV26-282)
→ No new info (linked only)
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.ptc.com/en/support/article/CS473270
CWECWE-20, CWE-502
PublishedJun 18, 2026
Last enriched55d agov7
Tags
rcecriticalvulnerabilityinput validationunsafe deserializationknown exploited vulnerabilitiesjsp webshells
Trending Score81
Source articles16
Independent10
Info Completeness10/14
Missing: cvss, epss, kev, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (3)

NONECVE-2026-77646EXP
Server Side Request Forgery (SSRF) vulnerability reported in Windchill
Trending: 39
NONECVE-2026-77644
Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliability (WRR) Enterprise Edition
Trending: 32
NONECVE-2026-77645
Critical Remote Code Execution (RCE) vulnerability reported in Windchill
Trending: 25

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 18, 2026
Added to CISA KEV
Jun 18, 2026
Discovered by ZDM
Jun 18, 2026
Updated: description, severity, tags
Jun 18, 2026
Updated: affectedVersions, cweIds
Jun 19, 2026
Updated: description, severity, iocs
Jun 26, 2026
Updated: description
Jun 26, 2026
Updated: description, tags
Jun 27, 2026
Updated: tags
Jun 29, 2026
Actively Exploited
Aug 1, 2026
Exploit Available
Aug 1, 2026
Patch Available
Aug 1, 2026

Version History

v7
Last enriched 55d ago
v7Tier D55d ago

Updated product name to FlexPLM, added new tags related to known exploited vulnerabilities and JSP webshells.

tags
via Help Net Security
v6Tier D58d ago

Updated severity to CRITICAL, added CVSS score of 9.3, and included new indicators of compromise and a new patch version.

descriptiontags
via CSO Online
v5Tier D58d ago

Updated description with new technical details, changed severity to CRITICAL, and updated CVSS score to 9.3, along with new IoCs.

description
via The Hacker News
v4Tier D58d ago

Updated description with technical details, changed severity to HIGH, and added IoCs.

descriptionseverityiocs
via SecurityWeek
v3Tier D65d ago

Updated description with technical details, added affected version 11.0 M030, changed severity to CRITICAL, updated CVSS score to 10.0, and provided patch release date of 15.06.2026.

affectedVersionscweIds
via Heise Security
v2Tier C67d ago

Updated severity to CRITICAL, added new description with details on improper input validation, and noted that no exploit is available.

descriptionseveritytags
via VulDB
v167d ago

Initial creation