CVE-2026-12569
Published Jun 18, 2026
Last updated 14 days ago
AI description
CVE-2026-12569 is a remote code execution (RCE) vulnerability found in PTC Windchill PDMlink and PTC FlexPLM. This flaw arises from improper input validation and the deserialization of untrusted data. An unauthenticated, remote attacker can exploit this vulnerability by sending specially crafted requests to the affected systems, enabling them to execute arbitrary code. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog, indicating that it is being actively exploited in the wild. Attackers have been observed deploying persistent JSP webshells to facilitate remote command execution and data exfiltration.
- Description
- A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
- Source
- 0b655efc-079c-4cb9-9e8d-164871239f4e
- NVD status
- Analyzed
- Products
- flexplm, windchill_pdmlink
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:X/U:Red
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- PTC Windchill and FlexPLM Improper Input Validation Vulnerability
- Exploit added on
- Jun 25, 2026
- Exploit action due
- Jun 28, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 0b655efc-079c-4cb9-9e8d-164871239f4e
- CWE-20
- Hype score
- Not currently trending
ACTIVE EXPLOIT: CISA adds CVE-2026-12569 (PTC Windchill/FlexPLM input validation) and CVE-2026-20230 (Cisco Unified Communications Manager SSRF) to Known Exploited Vulnerabilities Catalog. Federal agencies must prioritize patches under BOD 26-04; all orgs urged to follow
@ThreatPing
28 Jun 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PTC Windchill: CISA setzt CVE-2026-12569 auf KEV-Liste CISA hat CVE-2026-12569 in PTC Windchill und FlexPLM am 25. Juni 2026 in den KEV https://t.co/9QAAGW7Ztr https://t.co/94kfIa3aWD
@schoenfelderED
28 Jun 2026
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ACTIVE EXPLOIT: CISA added CVE-2026-12569 (PTC Windchill/FlexPLM input validation) and CVE-2026-20230 (Cisco Unified Communications Manager SSRF) to its Known Exploited Vulnerabilities Catalog. Federal agencies must prioritize patches under BOD 26-04; all orgs should follow suit
@ThreatPing
27 Jun 2026
6 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilità Amazon Q Developer e PTC Windchill: patch urgenti CVE-2026-12957 e CVE-2026-12569 Sicurezza Informatica, AWS https://t.co/KPEqjEPV5t https://t.co/D7Ixam3qN4
@matricedigitale
27 Jun 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/3 CISA added a critical PTC Windchill RCE to its KEV catalog after confirming active exploitation. CVE-2026-12569 (CVSS 9.3) lets attackers run code via deserialization of untrusted data. Patched last week, but attacks continue. #CVE #PTCWindchill #RCE #cybersecurity #KEV
@CyberTLDR
27 Jun 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
A CVSS 9.8 unauth RCE just landed on the system that holds your CAD, BOMs and engineering IP. PTC Windchill CVE-2026-12569 is in CISA's KEV — and the JSP web shell survives the patch you just applied. https://t.co/9iUvsX9cdL #CVE #Manufacturing #PLM https://t.co/cD5qv2NJTw
@zerohuntai
27 Jun 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-12569: PTC Windchill Exploitation — Detection and Remediation Guide "CISA adds CVE-2026-12569 to its KEV catalog. Defend against active unauthenticated RCE in PTC…" 🔗 https://t.co/uVXPByoZix #CyberSecurity #ThreatIntel #cve #zeroday #patcht
@SecurityAr58409
26 Jun 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-12569 in PTC Windchill & FlexPLM. CVSS allows unauthenticated RCE via malicious network request. Added to CISA KEV—patch by 2026-06-28. #CVE #ThreatIntel #DFIR https://t.co/mFYslXfjEH
@DFIR_Lab
26 Jun 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ ️We added PTC Windchill & FlexPLM improper input validation vulnerability CVE-2026-12569 and Cisco Unified Communications Manager vulnerability CVE-2026-20230 to our Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks
@CISACyber
25 Jun 2026
6947 Impressions
8 Retweets
25 Likes
3 Bookmarks
4 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ptc:flexplm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9645DC27-47FD-4E68-A73F-380DE6AB9265",
"versionEndIncluding": "11.0m030",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:11.1m020:*:*:*:*:*:*:*",
"matchCriteriaId": "1BA9771B-C606-4B0D-ADF1-E0BEA4FD5407",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:11.2.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "AF4D5C35-1E36-4A6E-86AA-5E26F5375E84",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:12.0.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "2A5BC13C-CBF4-4EA8-B5B7-E680BF7B22DA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:12.0.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0A7DB804-FA55-456C-8C58-7ACBDA710F45",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:12.1.3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "AABF3817-5BA7-4604-92D3-468B73EEDA75",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:13.0.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "33798622-E630-4F62-B675-01BFC99E73CC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:flexplm:13.0.3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "5D992EFD-F674-4217-9078-FAD2558168D5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A8E8CEE8-BECD-4D33-B14F-BA015EF0E39F",
"versionEndExcluding": "11.0m030",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:11.0m030:-:*:*:*:*:*:*",
"matchCriteriaId": "C456B19A-8A53-47AA-8C44-D7E4A99D73D0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:11.1m020:-:*:*:*:*:*:*",
"matchCriteriaId": "6B33DB9C-7883-495B-ACFF-31422ED4A256",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:11.2.1.0:-:*:*:*:*:*:*",
"matchCriteriaId": "631EB791-4C82-4A73-8793-465576C47EC2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:12.0.2.0:-:*:*:*:*:*:*",
"matchCriteriaId": "5AAE2484-F8D6-4842-93E3-EAA12469B800",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:12.1.2.0:-:*:*:*:*:*:*",
"matchCriteriaId": "FC145374-1ABE-4067-9649-EEE6D031C139",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:13.0.2.0:-:*:*:*:*:*:*",
"matchCriteriaId": "925FF6A1-A0A0-4B0F-878A-53CE23ECF2D3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:13.1.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D9658DCC-7527-4BDE-BEC1-D5C43A7C7B83",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:13.1.1.0:-:*:*:*:*:*:*",
"matchCriteriaId": "6619674F-DABA-420B-88BC-0CFDF2972309",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:13.1.2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0FF72930-943F-4A01-BC2A-6AEACBD38908",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:ptc:windchill_pdmlink:13.1.3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "AD29599D-F30B-4664-A8F7-59C256ABAB61",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]