Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-12569

Published 2026-06-18
Updated 2 months ago
Vendor/s
PTC
Product/s
Windchill and FlexPLM
Version/s
* > 11.0m030
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical RCE vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM allows unauthenticated remote exploitation. Patch immediately.

CPE

PTC logo
PTC
Product Version Start Version End (excl.) Status
flexplm * 11.0m030 vulnerable
flexplm 11.1m020 11.1m020 vulnerable
flexplm 11.2.1.0 11.2.1.0 vulnerable
flexplm 12.0.0.0 12.0.0.0 vulnerable
flexplm 12.0.2.0 12.0.2.0 vulnerable
flexplm 12.1.3.0 12.1.3.0 vulnerable
flexplm 13.0.2.0 13.0.2.0 vulnerable
flexplm 13.0.3.0 13.0.3.0 vulnerable
windchill_pdmlink * 11.0m030 vulnerable
windchill_pdmlink 11.0m030 11.0m030 vulnerable
windchill_pdmlink 11.1m020 11.1m020 vulnerable
windchill_pdmlink 11.2.1.0 11.2.1.0 vulnerable
windchill_pdmlink 12.0.2.0 12.0.2.0 vulnerable
windchill_pdmlink 12.1.2.0 12.1.2.0 vulnerable
windchill_pdmlink 13.0.2.0 13.0.2.0 vulnerable
windchill_pdmlink 13.1.0.0 13.1.0.0 vulnerable
windchill_pdmlink 13.1.1.0 13.1.1.0 vulnerable
windchill_pdmlink 13.1.2.0 13.1.2.0 vulnerable
windchill_pdmlink 13.1.3.0 13.1.3.0 vulnerable

Related weakness (CWE)

CWE-20, CWE-502

Remediation plan

1

Apply official patches

Consult PTC security advisory CS473270 to download and apply the specific Critical Patch Sets (CPS) for your version of Windchill PDMLink or FlexPLM.

2

Update affected systems

Ensure systems are upgraded beyond the identified vulnerable versions, including 11.0 M030, 12.0.2.0, and 13.1.3.0, following the specific patch path provided by PTC.

3

Restrict access

Limit network access to Windchill and FlexPLM interfaces to authorized users via VPN or internal networks, and implement strict firewall rules to block untrusted external traffic.

4

Monitor for exploitation

Conduct a forensic triage of PLM server logs for signs of suspicious Java deserialization activity, unauthorized remote command execution, or unusual child processes.

Detection Guidance

"Monitor web server and application logs for unusual Java deserialization errors or unexpected incoming traffic to PDMlink endpoints. Look for suspicious child processes spawned by the PTC application service, such as cmd.exe or /bin/sh. Security teams should also deploy network signatures to detect common deserialization gadget chains (e.g., CommonsCollections) being sent to the affected PLM ports, which may indicate an exploitation attempt."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management