CVE-2026-12569

Published Jun 18, 2026

Last updated 14 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-12569 is a remote code execution (RCE) vulnerability found in PTC Windchill PDMlink and PTC FlexPLM. This flaw arises from improper input validation and the deserialization of untrusted data. An unauthenticated, remote attacker can exploit this vulnerability by sending specially crafted requests to the affected systems, enabling them to execute arbitrary code. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog, indicating that it is being actively exploited in the wild. Attackers have been observed deploying persistent JSP webshells to facilitate remote command execution and data exfiltration.

Description
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
Source
0b655efc-079c-4cb9-9e8d-164871239f4e
NVD status
Analyzed
Products
flexplm, windchill_pdmlink

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:Red
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
Exploit added on
Jun 25, 2026
Exploit action due
Jun 28, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

0b655efc-079c-4cb9-9e8d-164871239f4e
CWE-20

Social media

Hype score
Not currently trending
  1. ACTIVE EXPLOIT: CISA adds CVE-2026-12569 (PTC Windchill/FlexPLM input validation) and CVE-2026-20230 (Cisco Unified Communications Manager SSRF) to Known Exploited Vulnerabilities Catalog. Federal agencies must prioritize patches under BOD 26-04; all orgs urged to follow

    @ThreatPing

    28 Jun 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. PTC Windchill: CISA setzt CVE-2026-12569 auf KEV-Liste CISA hat CVE-2026-12569 in PTC Windchill und FlexPLM am 25. Juni 2026 in den KEV https://t.co/9QAAGW7Ztr https://t.co/94kfIa3aWD

    @schoenfelderED

    28 Jun 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ACTIVE EXPLOIT: CISA added CVE-2026-12569 (PTC Windchill/FlexPLM input validation) and CVE-2026-20230 (Cisco Unified Communications Manager SSRF) to its Known Exploited Vulnerabilities Catalog. Federal agencies must prioritize patches under BOD 26-04; all orgs should follow suit

    @ThreatPing

    27 Jun 2026

    6 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Vulnerabilità Amazon Q Developer e PTC Windchill: patch urgenti CVE-2026-12957 e CVE-2026-12569 Sicurezza Informatica, AWS https://t.co/KPEqjEPV5t https://t.co/D7Ixam3qN4

    @matricedigitale

    27 Jun 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 1/3 CISA added a critical PTC Windchill RCE to its KEV catalog after confirming active exploitation. CVE-2026-12569 (CVSS 9.3) lets attackers run code via deserialization of untrusted data. Patched last week, but attacks continue. #CVE #PTCWindchill #RCE #cybersecurity #KEV

    @CyberTLDR

    27 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. A CVSS 9.8 unauth RCE just landed on the system that holds your CAD, BOMs and engineering IP. PTC Windchill CVE-2026-12569 is in CISA's KEV — and the JSP web shell survives the patch you just applied. https://t.co/9iUvsX9cdL #CVE #Manufacturing #PLM https://t.co/cD5qv2NJTw

    @zerohuntai

    27 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🔒 #CyberSecurity CVE-2026-12569: PTC Windchill Exploitation — Detection and Remediation Guide "CISA adds CVE-2026-12569 to its KEV catalog. Defend against active unauthenticated RCE in PTC…" 🔗 https://t.co/uVXPByoZix #CyberSecurity #ThreatIntel #cve #zeroday #patcht

    @SecurityAr58409

    26 Jun 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CRITICAL: CVE-2026-12569 in PTC Windchill & FlexPLM. CVSS allows unauthenticated RCE via malicious network request. Added to CISA KEV—patch by 2026-06-28. #CVE #ThreatIntel #DFIR https://t.co/mFYslXfjEH

    @DFIR_Lab

    26 Jun 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛡️ ️We added PTC Windchill & FlexPLM improper input validation vulnerability CVE-2026-12569 and Cisco Unified Communications Manager vulnerability CVE-2026-20230 to our Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks

    @CISACyber

    25 Jun 2026

    6947 Impressions

    8 Retweets

    25 Likes

    3 Bookmarks

    4 Replies

    1 Quote

Configurations